Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HubSpot Jinjava 信息泄露漏洞
Vulnerability Description
HubSpot Jinjava是美国HubSpotn个人开发者的一个应用软件。提供基于Java的模板模板引擎,基于Django模板语法,适用于呈现jinja模板。 Jinjava 中存在安全漏洞。该漏洞源于允许通过调用传递到Jinjava上下文的对象上的Java方法来访问任意类。这可能允许滥用应用程序类加载器,包括任意文件泄漏。以下产品及版本受到影响:Jinjava 2.5.4 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A