Описание
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.
A flaw was found in Thymeleaf, a server-side Java template engine. A security bypass vulnerability exists in its expression execution mechanisms, allowing specific constructs to be executed even in restricted sandboxed contexts. If an application developer passes unsanitized variables containing malicious expressions to the template engine, a remote attacker could exploit this to achieve Server-Side Template Injection (SSTI), potentially leading to arbitrary code execution.
Отчет
This is an Important security bypass in Thymeleaf's expression execution, allowing Server-Side Template Injection (SSTI). The flaw enables arbitrary code execution if an application processes unsanitized input containing malicious expressions within sandboxed template contexts. Red Hat OpenShift Dev Spaces is not affected by this vulnerability as each version ships with a patched version of Thymeleaf 3.1.5.RELEASE. Thymeleaf is only used in Red Hat OpenShift Dev Spaces for email generation rather than web request handling which limits the severity of this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | thymeleaf | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | thymeleaf | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | ||
| Red Hat Single Sign-On 7 | thymeleaf | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
9 Critical
CVSS3
Связанные уязвимости
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.
Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
Уязвимость JavaScript-движка Thymeleaf, связанная с непринятием мер по нейтрализации специальных элементов, используемых в операторе языка выражений, позволяющая нарушителю реализовать атаку внедрения шаблонов на стороне сервера (Server Side Template Injection (SSTI))
EPSS
9 Critical
CVSS3