First published: Thu Aug 17 2023(Updated: )
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Credit: security@opennms.com security@opennms.com security@opennms.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenNMS Horizon | <32.0.2 | |
OpenNMS Meridian | <2020.1.38 | |
OpenNMS Meridian | >=2021.1.0<2021.1.30 | |
OpenNMS Meridian | >=2022.1.0<2022.1.19 | |
OpenNMS Meridian | >=2023.1.0<2023.1.6 | |
maven/org.opennms:opennms-base-assembly | <32.0.2 | 32.0.2 |
<32.0.2 | ||
<2020.1.38 | ||
>=2021.1.0<2021.1.30 | ||
>=2022.1.0<2022.1.19 | ||
>=2023.1.0<2023.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-40313 is high, with a severity value of 8.8.
CVE-2023-40313 affects OpenNMS Horizon versions earlier than 32.0.2, allowing arbitrary remote Java code execution.
CVE-2023-40313 affects OpenNMS Meridian versions up to and including 2020.1.38, 2021.1.30, and 2022.1.19, allowing arbitrary remote Java code execution.
To fix CVE-2023-40313 in OpenNMS Horizon, upgrade to version 32.0.2 or newer.
To fix CVE-2023-40313 in OpenNMS Meridian, upgrade to version 2023.1.6, 2022.1.19, 2021.1.30, or 2020.1.38.