Description
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Dev Powers:ACF Color Coded Field Types Security Bypass (1.0)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-23969)
WordPress Plugin Hunk External Links Cross-Site Scripting (3.0.5)
WordPress 4.1.x Denial of Service Vulnerability (4.1 - 4.1.22)