Lucene search

K
osvGoogleOSV:CVE-2019-19999
HistoryDec 26, 2019 - 4:15 a.m.

CVE-2019-19999

2019-12-2604:15:10
Google
osv.dev
5

7.2 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.5%

Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.

7.2 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.5%

Related for OSV:CVE-2019-19999