CVE-2020-12873
A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.67% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- atlassian/alfresco enterprise content management
- Source
- cve@mitre.org
References
- https://issues.alfresco.com/jira/browse/MNT-21510Issue Tracking, Permissions Required, Vendor Advisory
- https://securitylab.github.com/advisories/GHSL-2020-039-alfrescoThird Party Advisory
- https://issues.alfresco.com/jira/browse/MNT-21510Issue Tracking, Permissions Required, Vendor Advisory
- https://securitylab.github.com/advisories/GHSL-2020-039-alfrescoThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.