GHSL-2020-039: Server-side template injection in Alfresco - CVE-2020-12873
Published Jul 15, 2020
·Updated
A user with privileges to edit a FreeMarker template (e.g. a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Affected Software
1 affected component
Alfresco Alfresco
Event History
Jul 15, 2020
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2020-039?
GHSL-2020-039 has a risk rating of 60, indicating a significant threat to systems.
2
How do I fix GHSL-2020-039?
To fix GHSL-2020-039, ensure you update Alfresco to the latest version that addresses the vulnerability.
3
What types of attacks can occur due to GHSL-2020-039?
GHSL-2020-039 allows an attacker to execute arbitrary Java code or run system commands, leading to potential data compromise.
4
Who is affected by GHSL-2020-039?
Any user with privileges to edit FreeMarker templates in Alfresco is at risk from GHSL-2020-039.
5
Is there any workaround for GHSL-2020-039?
Until a fix is applied for GHSL-2020-039, it is advised to restrict access privileges for users who can edit FreeMarker templates.