[MAVEN:GHSA-R6FX-55X3-F9X6] Crafter CMS Crafter Studio vulnerable to Improper Control of Dynamically-Managed Code Resources

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.

Package Affected Version
pkg:maven/org.craftercms/crafter-studio >= 3.1.0, < 3.1.18
Package Fixed Version
pkg:maven/org.craftercms/crafter-studio = 3.1.18
ID
MAVEN:GHSA-R6FX-55X3-F9X6
Severity
high
URL
https://github.com/advisories/GHSA-r6fx-55x3-f9x6
Published
2022-05-17T00:00:34
(2 years ago)
Modified
2023-09-12T13:30:03
(12 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.craftercms/crafter-studio org.craftercms crafter-studio >= 3.1.0 < 3.1.18
Fixed pkg:maven/org.craftercms/crafter-studio org.craftercms crafter-studio = 3.1.18
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...