Описание
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
Ссылки
- Release NotesThird Party Advisory
- PatchPermissions RequiredThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
- PatchPermissions RequiredThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.4 (исключая)
cpe:2.3:a:hubspot:jinjava:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00328
Низкий
6.5 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
Unauthorized access to Class instance in Jinjava
EPSS
Процентиль: 55%
0.00328
Низкий
6.5 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-863