以下是这段漏洞描述的中文翻译: Apache FreeMarker 模板加载机制中存在路径遍历漏洞。如果攻击者能够向 FreeMarker 指定任意格式错误的 locale(区域设置)标识符,且启用了本地化查找配置(该配置默认启用),则可能触发此漏洞。 受影响版本: 该问题影响 Apache FreeMarker 2.2.0 至 2.3.34 版本。 修复与缓解措施: 建议用户升级至 2.3.35 版本。对于较早版本,也可通过禁用本地化查找功能来缓解此漏洞。 补充说明: 需要注意的是,即使在使用受影响版本时,可加载
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache FreeMarker | 2.2.0 ~ 2.3.34 | - |
|
| Apache Software Foundation | Apache FreeMarker | 2.2.0 ~ 2.3.34 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80354 | Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secr | |
| CVE-2026-80351 | Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod | |
| CVE-2026-80352 | Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author appl | |
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A | |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE | |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth | |
| CVE-2026-57822 | Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserializatio | |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r | |
| CVE-2026-67593 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth | |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to |
No comments yet