Description
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
Remediation
References
https://gitee.com/xiandafu/beetl/issues/I6RUIP
https://github.com/luelueking/Beetl-3.15.0-vuln-poc
Related Vulnerabilities
CVE-2022-24839 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml
CVE-2021-27515 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse
CVE-2019-10757 Vulnerability in maven package org.webjars.npm:knex
CVE-2020-7789 Vulnerability in maven package org.webjars.npm:node-notifier
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-webflux