PT-2023-26346 · Unknown+1 · Spring-Boot-Admin+1
P1N93R
·
Published
2023-07-14
·
Updated
2023-07-27
·
CVE-2023-38286
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thymeleaf versions 3.1.1.RELEASE and earlier
spring-boot-admin versions 3.1.1 and earlier
Description
The issue allows for a sandbox bypass via crafted HTML, which may be relevant for Server Side Template Injection (SSTI) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.
Recommendations
For Thymeleaf versions 3.1.1.RELEASE and earlier, update to version 3.1.2.RELEASE or later, which has added countermeasures for this sort of bypass.
For spring-boot-admin versions 3.1.1 and earlier, update to version 3.1.2 or later, which contains mitigations for the issue.
As a temporary workaround, consider disabling the MailNotifier feature in spring-boot-admin until a patch is available.
Restrict access to environment variables via the UI to minimize the risk of exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thymeleaf
Spring-Boot-Admin