CVE-2024-55660

EPSS 0.73%

SiYuan has an SSTI via /api/template/renderSprig

發布日:2024/12/11修改日:2024/12/12
也稱為:GHSA-4pjc-pwgq-q9jpGO-2024-3324

描述

### Summary Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables ### Impact Information leakage

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

參考連結(5)