Description
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Remediation
References
https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html
https://security.netapp.com/advisory/ntap-20221014-0001/
https://vuldb.com/?id.186365
Related Vulnerabilities
CVE-2021-23337 Vulnerability in maven package org.webjars:lodash
CVE-2013-2254 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2022-25857 Vulnerability in maven package org.yaml:snakeyaml
CVE-2022-27772 Vulnerability in maven package org.springframework.boot:spring-boot
CVE-2011-2481 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core