Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Beetl 安全漏洞
Vulnerability Description
Beetl是中国李家智(xiandafu)个人开发者的一个高速模板引擎。 Beetl v3.15.12版本及之前版本存在安全漏洞,该漏洞源于对黑名单过滤不严格。攻击者利用该漏洞可以远程执行代码。
CVSS Information
N/A
Vulnerability Type
N/A