Jinjava before 2.5.4 allow access to arbitrary classes by calling...
Vulnerability Description
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12668
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/HubSpot/jinjava/compare/jinjava-2.5.3...jinjava-2.5.4
- https://github.com/HubSpot/jinjava/pull/426/commits/5dfa5b87318744a4d020b66d5f7747acc36b213b
- https://github.com/HubSpot/jinjava/pull/435/commits/1b9aaa4b420c58b4a301cf4b7d26207f1c8d1165
- https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.5.4
- https://securitylab.github.com/advisories/GHSL-2020-072-hubspot_jinjava
Affected Vendor
hubspot
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.