CVE-2021-35450

Source
https://cve.org/CVERecord?id=CVE-2021-35450
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35450.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-35450
Published
2021-08-02T20:15:08.210Z
Modified
2026-07-08T23:58:56.998457Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with command execution via freemarker.template.utility.Execute

References

Affected packages

Git / github.com/entando/entando-admin-console

Affected ranges

Type
GIT
Repo
https://github.com/entando/entando-admin-console
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:entando:admin_console:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.3.9"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
pia-crs4
v4.*
v4.2.0
v4.3.2-RC1
v5.*
v5.0.0-pre
v6.*
v6.2.0-sprint1-rc
v6.2.0-sprint2-rc
v6.2.0-sprint3-rc
v6.2.0-sprint4-rc
v6.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35450.json"