Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2021-0183 Moderate: Apache Velocity Code Execution Threat

mageia
Calendar Grey April 12, 2021
Dist Mageia Esm H88
Revised Velocity modules rectify a vulnerability within Apache Velocity that permits code execution by malicious actors.
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet c...

Summary

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2 (CVE-2020-13936).

References

- https://bugs.mageia.org/show_bug.cgi?id=28681

- https://www.openwall.com/lists/oss-security/2021/03/10/1

- https://www.cve.org/CVERecord?id=CVE-2020-13936

Resolution

SRPMS

- 8/core/velocity-1.7-33.1.mga8

- 7/core/velocity-1.7-22.1.mga7

Publication date: 12 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0183.html
Type: security
CVE: CVE-2020-13936

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here