Description
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
Remediation
References
https://gitee.com/xiandafu/beetl/issues/I6RUIP
https://github.com/luelueking/Beetl-3.15.0-vuln-poc
Related Vulnerabilities
CVE-2023-23848 Vulnerability in maven package org.jenkins-ci.plugins:synopsys-coverity
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2020-15366 Vulnerability in maven package org.webjars.bowergithub.ajv-validator:ajv
CVE-2020-21125 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2022-45207 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system