The vendor explicitly identifies these products as affected by this CVE.
- thymeleaf as a component of Red Hat Fuse 7
- spring-boot-starter-thymeleaf as a component of Red Hat Single Sign-On 7
- thymeleaf as a component of Red Hat Single Sign-On 7
- thymeleaf-extras-java8time as a component of Red Hat Single Sign-On 7
- thymeleaf-spring5 as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Thymeleaf, a server-side Java template engine. An unauthenticated remote attacker can exploit a security bypass vulnerability in the expression execution mechanisms. By providing unvalidated user input directly to the template engine, the attacker can bypass the library's protections, leading to Server-Side Template Injection (SSTI). This allows access to potentially sensitive objects from within a template.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
