CVE-2025-1686
- EPSS 0.78%
- Veröffentlicht 27.02.2025 05:15:14
- Zuletzt bearbeitet 05.06.2026 15:16:46
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification temp...
CVE-2022-37767
- EPSS 1.09%
- Veröffentlicht 12.09.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:15:07
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, a...
CVE-2019-19899
- EPSS 1.28%
- Veröffentlicht 19.12.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:37
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lan...