Search/CVE-2020-13936
CVE — High

CVE-2020-13936

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

CVSS v3.1
8.8 HIGH
EPSS
22.7%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Timeline
disclosure → media coverage
Mar 10, 2021
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024