GHSA-fv3m-xhqw-9m79

    Dashboard / Vulnerabilities / GHSA-fv3m-xhqw-9m79

    GHSA-fv3m-xhqw-9m79

    Published: 27 Apr 2022Last Modified: 8 Nov 2023

    Summary: ballcat-codegen template engine remote code execution injection

    Details: ### Impact Ballcat Codegen provides the function of online editing code to generate templates. In version < 1.0.0.beta.2, since Velocity and freemarker templates are introduced but input verification is not done, attackers can implement remote code execution through malicious code injection of the template engine. ### Patches The fault is rectified and needs to be upgraded to the latest version.

    Affected packages

    Package

    Name: com.hccake:ballcat-codegen

    Purl: pkg:maven/com.hccake/ballcat-codegen

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.0.beta.2

    Affected versions

    0.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fv3m-xhqw-9m79 | CVE-DB