CVE-2023-45303
Summary
| CVE | CVE-2023-45303 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-06 19:15:00 UTC |
| Updated | 2023-10-12 18:10:00 UTC |
| Description | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint). |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995597 Java (Maven) Security Update for org.thingsboard:thingsboard (GHSA-6pgr-j9v4-xfvv)