Описание
ThingsBoard Server-Side Template Injection
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute for content sent to the /api/admin/settings endpoint.
Пакеты
Наименование
org.thingsboard:thingsboard
maven
Затронутые версииВерсия исправления
< 3.5
3.5
Связанные уязвимости
CVSS3: 8.4
nvd
больше 2 лет назад
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).