Lucene search

K
osvGoogleOSV:CVE-2020-12668
HistoryFeb 19, 2021 - 11:15 p.m.

CVE-2020-12668

2021-02-1923:15:12
Google
osv.dev
5
jinjava
arbitrary classes
application class loader
file disclosure

AI Score

7

Confidence

High

EPSS

0.001

Percentile

40.8%

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.

AI Score

7

Confidence

High

EPSS

0.001

Percentile

40.8%

Related for OSV:CVE-2020-12668