Impact
Apache FreeMarker implements a template loading mechanism that, when the localized lookup configuration is enabled, interprets the locale identifier as part of the path resolution. An attacker who can supply a malformed locale value can cause FreeMarker to load templates from paths that are outside the intended base directory. This flaw allows the attacker to read files that may contain sensitive configuration or code if the underlying TemplateLoader permits access beyond the configured base location. The vulnerability is identified as CWE‑23 and can lead to information disclosure without requiring authentication or privileged execution, depending on the application’s configuration.
Affected Systems
Apache FreeMarker versions from 2.2.0 through 2.3.34 are affected. The default localized lookup feature is enabled in these releases. Apache Software Foundation maintains the product. The vulnerability does not affect versions 2.3.35 and newer, which contain the fix.
Risk and Exploitability
The CVSS base score of 9.1 indicates high severity. The EPSS score is less than 1 %, suggesting the exploitation probability is low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote input that supplies a malformed locale value, such as a web‑request parameter, making the flaw potentially exploitable in any publicly reachable FreeMarker‑based application. The impact is limited to the scope of the TemplateLoader: with FileTemplateLoader the attacker can read files only within the configured baseDir, but other loaders may grant access to additional resources. Consequently, organizations should treat this as a critical issue and apply the official mitigation.
OpenCVE Enrichment
Github GHSA