The vendor explicitly identifies these products as affected by this CVE.
- thymeleaf as a component of Red Hat Fuse 7
- spring-boot-starter-thymeleaf as a component of Red Hat Single Sign-On 7
- thymeleaf as a component of Red Hat Single Sign-On 7
- thymeleaf-extras-java8time as a component of Red Hat Single Sign-On 7
- thymeleaf-spring5 as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Thymeleaf, a server-side Java template engine. An unauthenticated remote attacker can exploit this vulnerability by providing unvalidated user input to the template engine. This bypasses existing security mechanisms, allowing for the execution of unauthorized expressions and leading to Server-Side Template Injection (SSTI).
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
