Description
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1726 | Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2. |
Github GHSA |
GHSA-fv3m-xhqw-9m79 | ballcat-codegen template engine remote code execution injection |
References
History
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T18:14:01.853Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24881
Updated: 2024-08-03T04:29:00.661Z
Status : Modified
Published: 2022-04-26T16:15:47.737
Modified: 2024-11-21T06:51:18.673
Link: CVE-2022-24881
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA