Description
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051603
Related Vulnerabilities
CVE-2011-1419 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-1003025 Vulnerability in maven package org.jenkins-ci.plugins:cloudfoundry
CVE-2021-21602 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-3143 Vulnerability in maven package org.wildfly.security:wildfly-elytron-credential
CVE-2023-40336 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-folder