GHSA-fv3m-xhqw-9m79
Dashboard / Vulnerabilities / GHSA-fv3m-xhqw-9m79
Summary: ballcat-codegen template engine remote code execution injection
Details: ### Impact Ballcat Codegen provides the function of online editing code to generate templates. In version < 1.0.0.beta.2, since Velocity and freemarker templates are introduced but input verification is not done, attackers can implement remote code execution through malicious code injection of the template engine. ### Patches The fault is rectified and needs to be upgraded to the latest version.
References: https://github.com/ballcat-projects/ballcat-codegen/security/advisories/GHSA-fv3m-xhqw-9m79, https://nvd.nist.gov/vuln/detail/CVE-2022-24881, https://github.com/ballcat-projects/ballcat-codegen/issues/5, https://github.com/ballcat-projects/ballcat-codegen/commit/84a7cb38daf0295b93aba21d562ec627e4eb463b, https://github.com/ballcat-projects/ballcat-codegen
Affected packages
Package
Name: com.hccake:ballcat-codegen
Purl: pkg:maven/com.hccake/ballcat-codegen
Affected ranges
Type: ECOSYSTEM
Events:
