Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29563
HistoryMar 04, 2021 - 4:14 a.m.

Remote Code Execution

2021-03-0404:14:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
25

0.002 Low

EPSS

Percentile

61.0%

velocity-engine-core is vulnerable to remote code execution. The Uberspector fails to prevent access to java.lang.ClassLoader methods and allows an attacker that is able to modify Template contents to execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container.

References