Description
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051601
Related Vulnerabilities
CVE-2017-12619 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2020-2143 Vulnerability in maven package org.jenkins-ci.plugins:logstash
CVE-2019-10320 Vulnerability in maven package org.jenkins-ci.plugins:credentials
CVE-2021-41184 Vulnerability in npm package jquery-ui
CVE-2020-1960 Vulnerability in maven package org.apache.flink:flink-metrics-core