Posted by evan via Fulldisclosure on Sep 26 SUMMARY: an authenticated deserialization vuln in openEQUELLA allows an attacker to inject a SignedObject payload, unwrap the SignedObject, create an LDAP callback and serve a JNR response to get the server to execute arbitrary code. alongside this sink is a SSTI vuln as well. https://blog.evan.lat/posts/openeq/ openequella is an "open source digital repository" for educational material. it is widely used in australian…

Read the full article at Full Disclosure →