{"id":"GHSA-qcj6-jqrg-4wp2","summary":"Template injection in thymeleaf-spring5","details":"In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.","aliases":["CVE-2021-43466"],"modified":"2024-02-20T05:33:13.432414Z","published":"2021-11-10T19:52:33Z","database_specific":{"github_reviewed_at":"2021-11-10T18:12:25Z","nvd_published_at":"2021-11-09T12:15:00Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43466"},{"type":"WEB","url":"https://github.com/thymeleaf/thymeleaf-spring/issues/263#issuecomment-977199524"},{"type":"WEB","url":"https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html"},{"type":"PACKAGE","url":"https://github.com/thymeleaf/thymeleaf-spring"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20221014-0001"},{"type":"WEB","url":"https://vuldb.com/?id.186365"}],"affected":[{"package":{"name":"org.thymeleaf:thymeleaf-spring5","ecosystem":"Maven","purl":"pkg:maven/org.thymeleaf/thymeleaf-spring5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.13.RELEASE"}]}],"versions":["3.0.10.RELEASE","3.0.11.RELEASE","3.0.12.RELEASE","3.0.3.M1","3.0.4.M2","3.0.5.M3","3.0.6.M4","3.0.7.RC1","3.0.8.RELEASE","3.0.9.RELEASE"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.12.RELEASE","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-qcj6-jqrg-4wp2/GHSA-qcj6-jqrg-4wp2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}