CVE-2019-19999
26.12.2019, 04:15
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
Vendor | Product | Version |
---|---|---|
halo | halo | 𝑥 ≤ 1.1.1 |
halo | halo | 1.1.3:beta1 |
halo | halo | 1.1.3:beta2 |
halo | halo | 1.2.0:beta1 |
𝑥
= Vulnerable software versions
References