Description
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Remediation
References
https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html
https://vuldb.com/?id.186365
https://security.netapp.com/advisory/ntap-20221014-0001/
Related Vulnerabilities
CVE-2020-7709 Vulnerability in npm package json-pointer
CVE-2022-41881 Vulnerability in maven package io.netty:netty-codec-haproxy
CVE-2022-0144 Vulnerability in npm package shelljs
CVE-2021-23329 Vulnerability in npm package nested-object-assign
CVE-2022-34113 Vulnerability in maven package io.dataease:dataease-plugin-common