Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hjr-fg6c-v2h6

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Unauthorized access to Class instance in Jinjava

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.

Пакеты

Наименование

com.hubspot.jinjava:jinjava

maven
Затронутые версииВерсия исправления

< 2.5.4

2.5.4

EPSS

Процентиль: 55%
0.00328
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.

EPSS

Процентиль: 55%
0.00328
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200