Description
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
Remediation
References
https://github.com/HubSpot/jinjava/pull/230
https://github.com/HubSpot/jinjava/blob/master/CHANGES.md
Related Vulnerabilities
CVE-2021-23356 Vulnerability in npm package kill-process-by-name
CVE-2021-3805 Vulnerability in npm package object-path
CVE-2021-26707 Vulnerability in maven package org.webjars.npm:merge-deep
CVE-2021-3777 Vulnerability in npm package tmpl
CVE-2018-12022 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind