PT-2024-19473 · Beetl · Beetl

Wooclee

·

Published

2024-02-01

·

Updated

2025-06-06

·

CVE-2024-22533

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Beetl versions prior to 3.15.12
Description The rendering template in Beetl has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. However, because the blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
Recommendations For versions prior to 3.15.12, update to version 3.15.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the rendering template to minimize the risk of exploitation. Additionally, ensure that the incoming template is not controllable by an attacker to prevent bypassing the DefaultNativeSecurityManager blacklist.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-22533
GHSA-9GH8-877R-G477

Affected Products

Beetl