[MAVEN:GHSA-M69H-4FRQ-VWQ7] Server-side template injection in beetl

Severity Critical
Affected Packages 1
CVEs 1

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

Package Affected Version
pkg:maven/com.ibeetl/beetl <= 3.15.0.RELEASE
ID
MAVEN:GHSA-M69H-4FRQ-VWQ7
Severity
critical
URL
https://github.com/advisories/GHSA-m69h-4frq-vwq7
Published
2023-05-04T03:30:22
(16 months ago)
Modified
2023-11-08T05:07:09
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.ibeetl/beetl com.ibeetl beetl <= 3.15.0.RELEASE
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...