GHSA-c3mp-9vx3-2rvv · Severity: high · Ecosystem: maven — OpenNMS Horizon RCE via JEXL2 expression
OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.
Conclusion & alert: CVE-2021-3396 is rated Moderate Risk (64.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.43%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-19 | 2.49% | 2.43% | -0.06% |
| 2 | 2025-03-30 | 10.52% | 2.49% | -8.03% |
| 3 | 2025-03-29 | — | 10.52% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.5 | 2.0 | MEDIUM |
|
8.0 | 6.4 | [email protected] |
GHSA-c3mp-9vx3-2rvv · Severity: high · Ecosystem: maven — OpenNMS Horizon RCE via JEXL2 expression
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| opennms | horizon | >= 16.0.0, <= 27.0.3 | cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:* |
| opennms | meridian | >= 2016.1.0, <= 2016.1.24 | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
| opennms | meridian | >= 2017.1.0, <= 2017.1.26 | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
| opennms | meridian | >= 2018.1.0, < 2018.1.25 | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
| opennms | meridian | >= 2019.1.0, < 2019.1.16 | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
| opennms | meridian | >= 2020.1.0, < 2020.1.5 | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
| opennms | newts | < 1.5.3 | cpe:2.3:a:opennms:newts:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.opennms.com | Vendor Advisory |
| https://www.opennms.com/en/blog/2021-02-16-cve-2021-3396-full-security-disclosure/ | Vendor Advisory |