Sandbox Bypass in Apache Velocity Engine
High severity
GitHub Reviewed
Published
Jan 6, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 10, 2021
Reviewed
Mar 17, 2021
Published to the GitHub Advisory Database
Jan 6, 2022
Last updated
Feb 1, 2023
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
References