Description
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
Remediation
References
https://gitee.com/xiandafu/beetl/issues/I6RUIP
https://github.com/luelueking/Beetl-3.15.0-vuln-poc
Related Vulnerabilities
CVE-2021-33605 Vulnerability in maven package com.vaadin:vaadin-checkbox-flow
CVE-2022-0639 Vulnerability in npm package url-parse
CVE-2017-16139 Vulnerability in npm package jikes
CVE-2023-26120 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2022-29648 Vulnerability in maven package com.jflyfox:jflyfox_jfinal