GHSA-m69h-4frq-vwq7

Suggest an improvement
Source
https://github.com/advisories/GHSA-m69h-4frq-vwq7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-m69h-4frq-vwq7/GHSA-m69h-4frq-vwq7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m69h-4frq-vwq7
Aliases
  • CVE-2023-30331
Published
2023-05-04T03:30:22Z
Modified
2024-11-29T05:42:29.017157Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Server-side template injection in beetl
Details

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

Database specific
{
    "nvd_published_at": "2023-05-04T03:15:21Z",
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-05T02:21:41Z"
}
References

Affected packages

Maven / com.ibeetl:beetl

Package

Name
com.ibeetl:beetl
View open source insights on deps.dev
Purl
pkg:maven/com.ibeetl/beetl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.15.0.RELEASE

Affected versions

2.*

2.2.5
2.2.6
2.2.7-snapshot
2.2.7
2.2.8
2.2.9
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15-snapshot
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.5.3
2.7.0
2.7.1
2.7.2
2.7.3
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.7.10
2.7.11
2.7.12
2.7.13
2.7.14
2.7.15
2.7.16
2.7.17
2.7.18
2.7.19
2.7.20
2.7.21
2.7.22
2.7.23
2.7.24
2.7.25
2.7.26
2.7.27
2.7.28
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
2.9.7
2.9.8
2.9.9
2.9.10

3.*

3.0.0.M1
3.0.0.M2
3.0.0.M3
3.0.0.M4
3.0.0.RELEASE
3.0.1.RELEASE
3.0.2.RELEASE
3.0.3.RELEASE
3.0.5.RELEASE
3.0.6.RELEASE
3.0.7.RELEASE
3.0.8.RELEASE
3.0.9.RELEASE
3.0.10.RELEASE
3.0.11.RELEASE
3.0.12.RELEASE
3.0.13.RELEASE
3.0.14.RELEASE
3.0.15.RELEASE
3.0.16.RELEASE
3.0.17.RELEASE
3.0.18.RELEASE
3.0.19.RELEASE
3.0.20.RELEASE
3.0.21.RELEASE
3.1.0.RELEASE
3.1.1.RELEASE
3.1.2.RELEASE
3.1.3.RELEASE
3.1.4.RELEASE
3.1.5.RELEASE
3.1.6.RELEASE
3.1.7.RELEASE
3.1.8.RELEASE
3.2.0.RELEASE
3.2.1.RELEASE
3.2.2.RELEASE
3.2.3.RELEASE
3.2.4.RELEASE
3.3.0.RELEASE
3.3.1.RELEASE
3.3.2.RELEASE
3.4.0.RELEASE
3.5.0.RELEASE
3.5.1.RELEASE
3.6.0.RELEASE
3.6.1.RELEASE
3.7.0.RELEASE
3.8.0.RELEASE
3.8.1.RELEASE
3.9.0.RELEASE
3.9.1.RELEASE
3.9.2.RELEASE
3.9.3.RELEASE
3.10.0.RELEASE
3.10.0.Antlr4.5-RELEASE
3.11.0.RELEASE
3.12.0.RELEASE
3.13.0.RELEASE
3.14.1.RELEASE
3.15.0.RELEASE