Description
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Remediation
References
https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html
https://security.netapp.com/advisory/ntap-20221014-0001/
https://vuldb.com/?id.186365
Related Vulnerabilities
CVE-2021-39178 Vulnerability in npm package next
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2022-0722 Vulnerability in npm package parse-url
CVE-2023-43961 Vulnerability in maven package cn.dev33:sa-token-core
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app