Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2020-12668
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
0
Attacker Value
Unknown
CVE-2018-18893
Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
0