Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2677 | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint). |
Github GHSA |
GHSA-6pgr-j9v4-xfvv | ThingsBoard Server-Side Template Injection |
Thu, 19 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-19T18:41:34.903Z
Reserved: 2023-10-06T00:00:00.000Z
Link: CVE-2023-45303
Updated: 2024-08-02T20:21:15.394Z
Status : Modified
Published: 2023-10-06T19:15:13.040
Modified: 2024-11-21T08:26:43.187
Link: CVE-2023-45303
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA