CVE-2019-14965: Code Injection
Published Aug 12, 2019
·Updated
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
Affected Software
1 affected component
Frappe frappe>=10.0.0<12.0.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 12, 2019
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14965?
CVE-2019-14965 is a server-side template injection (SSTI) vulnerability in Frappe Framework versions 10 through 12 before 12.0.4.
2
How severe is CVE-2019-14965?
CVE-2019-14965 has a severity rating of 9.8 (Critical).
3
How does CVE-2019-14965 affect Frappe Framework?
CVE-2019-14965 affects Frappe Framework versions 10 through 12 before 12.0.4.
4
How can I fix CVE-2019-14965?
To fix CVE-2019-14965, you should update Frappe Framework to version 12.0.4 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-14965?
The CWE ID for CVE-2019-14965 is CWE-94 (Improper Control of Generation of Code).