Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical severity
GitHub Reviewed
Published
Aug 28, 2025
in
valtimo-platform/valtimo-backend-libraries
•
Updated Aug 28, 2025
Package
Affected versions
< 12.16.0.RELEASE
>= 13.0.0.RELEASE, < 13.1.2.RELEASE
Patched versions
12.16.0.RELEASE
13.1.2.RELEASE
Description
Published to the GitHub Advisory Database
Aug 28, 2025
Reviewed
Aug 28, 2025
Published by the National Vulnerability Database
Aug 28, 2025
Last updated
Aug 28, 2025
Impact
Any admin that can create or modify and execute process-definitions could gain access to sensitive data or resources.
This includes but is not limited to:
Attack requirements
The following conditions have to be met in order to perform this attack:
Patches
Version 12.16.0 and 13.1.2 have been patched. It is strongly advised to upgrade.
Workarounds
If no scripting is needed in any of the processes, it could be possible to disable it altogether via the
ProcessEngineConfiguration
:Warning: this workaround could lead to unexpected side-effects. Please test thoroughly.
References
References