CVE-2020-13936
ADVISORY - githubSummary
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
EPSS Score: 0.10626 (0.929)
Common Weakness Enumeration (CWE)
ADVISORY - nist
ADVISORY - github
Improper Input Validation
ADVISORY - gitlab
ADVISORY - redhat
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in