Vulnerabilities
Vulnerable Software
Hubspot:  >> Jinjava  >> 2.0.4  Security Vulnerabilities
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-02-19
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
CVSS Score
5.3
EPSS Score
0.007
Published
2019-01-03


Contact Us

Shodan ® - All rights reserved