The user controlled twig templates rendering in Pimcore/Mail & ClassDefinition\Layout\Text is vulnerable to server-side template Injection RCE.
Update to version 10.5.9 or apply this patch manually https://github.com/pimcore/pimcore/pull/13347.patch
Apply https://github.com/pimcore/pimcore/pull/13347.patch manually.
Credits: @nth347 from Viettel Cyber Security
{
"nvd_published_at": "2022-10-27T15:15:00Z",
"severity": "CRITICAL",
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2022-10-29T00:29:08Z"
}