Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine
Vulnerability Description
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
将私有的资源传输到一个新的空间(资源泄露)
Vulnerability Title
Apache FreeMarker 安全漏洞
Vulnerability Description
Apache FreeMarker是美国阿帕奇(Apache)基金会的一个基于Java的模板引擎,最初专注于使用MVC软件架构生成动态网页。 Apache FreeMarker 存在安全漏洞,攻击者可利用该漏洞通过FreeMarker读取文本内容,包括文件脚本*、模板*和.git *(非二进制)中的一些文件。
CVSS Information
N/A
Vulnerability Type
N/A