Please patch CVEs for package codegen version 0.6.8 INFO (CVEs are): codegen 0.6.8 cves found CVE-2022-24881 Desc: Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2. Link: https://nvd.nist.gov/vuln/detail/CVE-2022-24881 Severity: CRITICAL
*** Bug 13697 has been marked as a duplicate of this bug. ***
*** Bug 13506 has been marked as a duplicate of this bug. ***
Эта уязвимость не для нашего проекта, это для https://github.com/ballcat-projects/ballcat-codegen У нас в репах https://github.com/mysema/codegen т.е. другой проект. https://abf.io/import/codegen
secteam_verified