QID 995597
Date Published: 2023-10-18
QID 995597: Java (Maven) Security Update for org.thingsboard:thingsboard (GHSA-6pgr-j9v4-xfvv)
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute for content sent to the /api/admin/settings endpoint.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6pgr-j9v4-xfvv for updates and patch information.
Vendor References
- GHSA-6pgr-j9v4-xfvv -
github.com/advisories/GHSA-6pgr-j9v4-xfvv
CVEs related to QID 995597
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6pgr-j9v4-xfvv | org.thingsboard:thingsboard |
|