Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-06-11T18:34:38.374Z

Updated: 2024-08-02T03:50:56.118Z

Reserved: 2024-06-05T20:10:46.497Z

Link: CVE-2024-37301

cve-icon Vulnrichment

Updated: 2024-06-11T20:21:15.403Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-11T19:16:07.890

Modified: 2024-11-21T09:23:34.073

Link: CVE-2024-37301

cve-icon Redhat

No data.