Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
{ "versions": [ { "introduced": "0" }, { "fixed": "2.5.4" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12668.json"