CVE Database
/

CVE-2020-13936

Back to search

CVE-2020-13936

Published: Mar 10, 2021

Modified: Feb 13, 2025

PUBLISHED

Description

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

VendorProductVersions

Apache Software Foundation

Apache Velocity Engine

affected
Apache Velocity Engine - <= 2.2

References

GLSA-202107-52
vendor-advisory
x_refsource_GENTOO
[activemq-users] 20210830 Security issues
mailing-list
x_refsource_MLIST

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now