Описание
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:thymeleaf:thymeleaf:3.0.12:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04592
Низкий
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-94
Связанные уязвимости
EPSS
Процентиль: 89%
0.04592
Низкий
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-94