Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28038
HistoryDec 04, 2020 - 12:52 a.m.

Template Injection

2020-12-0400:52:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.199 Low

EPSS

Percentile

96.4%

cron-utils is vulnerable to a template Injection vulnerability. The use of cron-utils with @Cron annotation allows an attacker to inject malicious Java EL expressions as it does not properly validate the untrusted Cron expressions, leading to a remote code execution.

CPENameOperatorVersion
cron-utilsle9.1.2

References

0.199 Low

EPSS

Percentile

96.4%