PT-2024-27459 · Unknown · Document Merge Service

C0Rydoras

·

Published

2024-06-11

·

Updated

2026-02-04

·

CVE-2024-37301

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Document Merge Service versions 6.5.1 and prior
Description The issue allows for remote code execution via server-side template injection, which can result in full takeover of the affected system when executed as root. This gives an attacker considerable control over the container, executed as the document-merge-server user with the UID 901.
Recommendations For versions 6.5.1 and prior, update to version 6.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the template merge API to minimize the risk of exploitation. Avoid using the PLACEHOLDER. class . mro [1]. subclasses () variable in templates until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-37301
GHSA-V5GF-R78H-55Q6

Affected Products

Document Merge Service