OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input
id: CVE-2024-41667
info:
name: OpenAM<=15.0.3 FreeMarker - Template Injection
author: iamnoooob
...