CVE-2015-0249: Code Injection
Published Jul 14, 2017
·Updated
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
Affected Software
2 affected components
Apache Roller=5.1.0
Apache Roller=5.1.1
Event History
Jul 14, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0249?
CVE-2015-0249 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0249?
To fix CVE-2015-0249, upgrade Apache Roller to version 5.1.2 or later.
3
Who is affected by CVE-2015-0249?
CVE-2015-0249 affects Apache Roller versions 5.1.0 and 5.1.1 where remote authenticated users with admin privileges are at risk.
4
What kind of attack can CVE-2015-0249 enable?
CVE-2015-0249 can enable remote authenticated attackers to execute arbitrary Java code on the server.
5
Is there a workaround for CVE-2015-0249?
Currently, the recommended solution for CVE-2015-0249 is to implement the upgrade to a patched version rather than relying on a workaround.