CVE-2019-19999: SSRF
Published Dec 26, 2019
·Updated
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFERRESOLVER is not used in the FreeMarker configuration.
Affected Software
4 affected components
Halo Halo<=1.1.1
Halo Halo=1.1.3-beta1
Halo Halo=1.1.3-beta2
Halo Halo=1.2.0-beta1
Remediation
Event History
Dec 26, 2019
CVE Published
via MITRE·03:38 AM
Data Sourced
via MITRE·03:38 AM
Description
Frequently Asked Questions
1
What is CVE-2019-19999?
CVE-2019-19999 is a vulnerability in the Halo CMS software before version 1.2.0-beta.1 that allows for Server Side Template Injection (SSTI) due to a misconfiguration in the FreeMarker configuration.
2
What is the severity of CVE-2019-19999?
The severity of CVE-2019-19999 is high with a severity value of 7.2.
3
How does CVE-2019-19999 affect Halo CMS?
CVE-2019-19999 affects Halo CMS versions 1.1.1, 1.1.3-beta1, 1.1.3-beta2, and 1.2.0-beta1.
4
How can I fix CVE-2019-19999?
To fix CVE-2019-19999, update Halo CMS to version 1.2.0-beta.1 or later.
5
Where can I find more information about CVE-2019-19999?
You can find more information about CVE-2019-19999 on the Halo CMS GitHub page, including the GitHub compare and issue links provided.