CVE-2022-37767
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from an untrusted source, or else the application using the engine should apply restrictions to the input. The engine is not responsible for validating the input.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- pebbletemplates/pebble templates
- Source
- cve@mitre.org
References
- https://github.com/PebbleTemplates/pebble/issues/625#issuecomment-1282138635Exploit, Issue Tracking, Third Party Advisory
- https://github.com/Y4tacker/Web-Security/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://github.com/PebbleTemplates/pebble/issues/625#issuecomment-1282138635Exploit, Issue Tracking, Third Party Advisory
- https://github.com/Y4tacker/Web-Security/issues/3Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.