漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Velocity.js: Prototype Pollution in #set path assignment
Vulnerability Description
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
Velocity.js 安全漏洞
Vulnerability Description
Velocity.js是Eward个人开发者的一个JavaScript实现的Apache Velocity模板引擎。 Velocity.js 2.1.5及之前版本存在安全漏洞,该漏洞源于处理#set指令时存在原型污染,攻击者可通过控制模板修改Object.prototype,可能导致拒绝服务或远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A