Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-11T18:34:38.374Z
Updated: 2024-08-02T03:50:56.118Z
Reserved: 2024-06-05T20:10:46.497Z
Link: CVE-2024-37301
Vulnrichment
Updated: 2024-06-11T20:21:15.403Z
NVD
Status : Awaiting Analysis
Published: 2024-06-11T19:16:07.890
Modified: 2024-11-21T09:23:34.073
Link: CVE-2024-37301
Redhat
No data.