Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22563
HistoryFeb 25, 2020 - 3:27 a.m.

Server-Side Template Injection

2020-02-2503:27:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.009 Low

EPSS

Percentile

82.4%

dropwizard-validation is vulnerable to server-side template injection. The vulnerability exists as ViolationCollector does not sanitize Java Expression Language (EL) expressions and accepts malicious Java EL expressions to be passed into the server-side template in the self-validating feature, allowing an attacker to execute arbitrary code on the server.

0.009 Low

EPSS

Percentile

82.4%