Логотип exploitDog
bind:CVE-2023-38286
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38286

Количество 2

Количество 2

nvd логотип

CVE-2023-38286

больше 2 лет назад

Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7gj7-224w-vpr3

больше 2 лет назад

Spring-boot-admin sandbox bypass via crafted HTML

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38286

Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7gj7-224w-vpr3

Spring-boot-admin sandbox bypass via crafted HTML

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу