Description
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Remediation
References
https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html
https://security.netapp.com/advisory/ntap-20221014-0001/
https://vuldb.com/?id.186365
Related Vulnerabilities
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2020-7656 Vulnerability in maven package org.fujion.webjars:jquery
CVE-2023-34617 Vulnerability in maven package com.owlike:genson
CVE-2020-8147 Vulnerability in npm package utils-extend
CVE-2020-35491 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind