Loading
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Use Apache vendor hub and Unomi product page to widen CVE-2020-11975 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-13942 and CVE-2021-31164 for nearby disclosures in the same product family.