Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Velocity.js: Prototype Pollution in #set path assignment
Vulnerability Description
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
Velocity.js 安全漏洞
Vulnerability Description
Velocity.js是Eward个人开发者的一个JavaScript实现的Apache Velocity模板引擎。 Velocity.js 2.1.5及之前版本存在安全漏洞,该漏洞源于处理#set指令时存在原型污染,攻击者可通过控制模板修改Object.prototype,可能导致拒绝服务或远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A