Description
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051601
Related Vulnerabilities
CVE-2020-5403 Vulnerability in maven package io.projectreactor.netty:reactor-netty
CVE-2019-1003035 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents
CVE-2017-4971 Vulnerability in maven package org.springframework.webflow:spring-webflow
CVE-2019-10373 Vulnerability in maven package org.jenkins-ci.plugins:build-pipeline-plugin
CVE-2019-10474 Vulnerability in maven package org.jenkins-ci.plugins:global-post-script