{"id":"GHSA-83m8-7hj8-ff5w","summary":"Pebble Templates Improper Input Validation vulnerability","details":"Pebble Templates prior to 3.1.4 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class `java.lang.Class.forName(java.lang.Module,java.lang.String)` signature.","aliases":["CVE-2019-19899"],"modified":"2024-02-16T08:24:22.841536Z","published":"2022-05-24T22:01:17Z","database_specific":{"cwe_ids":["CWE-20","CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-18T21:25:57Z","nvd_published_at":"2019-12-19T00:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19899"},{"type":"WEB","url":"https://github.com/PebbleTemplates/pebble/issues/493"},{"type":"WEB","url":"https://github.com/PebbleTemplates/pebble/pull/511"},{"type":"PACKAGE","url":"https://github.com/PebbleTemplates/pebble"},{"type":"WEB","url":"https://research.securitum.com/server-side-template-injection-on-the-example-of-pebble"}],"affected":[{"package":{"name":"io.pebbletemplates:pebble-project","ecosystem":"Maven","purl":"pkg:maven/io.pebbletemplates/pebble-project"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.4"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.2","3.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-83m8-7hj8-ff5w/GHSA-83m8-7hj8-ff5w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}