CVE-2020-13936

HIGH8.8EPSS 16.8%

Sandbox Bypass in Apache Velocity Engine

發布日:2022/1/6修改日:2024/3/15
也稱為:GHSA-59j4-wjwp-mw9mDEBIAN-CVE-2020-13936

描述

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(27)