CVE-2022-24881
Summary
| CVE | CVE-2022-24881 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-26 16:15:00 UTC |
| Updated | 2022-05-06 13:14:00 UTC |
| Description | Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| :lock: 修改模板引擎的默认安全策略,以防止RCE · ballcat-projects/ballcat-codegen@84a7cb3 · GitHub | MISC | github.com | |
| ballcat-codegen exists for template engine remote code execution injection · Advisory · ballcat-projects/ballcat-codegen · GitHub | CONFIRM | github.com | |
| ballcat-codegen template engine injection RCE · Issue #5 · ballcat-projects/ballcat-codegen · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.