Lucene search

K

Pebbletemplates Security Vulnerabilities

cve
cve

CVE-2022-37767

Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from.....

9.8CVSS

9.8AI Score

0.003EPSS

2022-09-12 02:15 PM
50
10
cve
cve

CVE-2019-19899

Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String)...

9.8CVSS

9.3AI Score

0.005EPSS

2019-12-19 12:15 AM
75