Pebbletemplates
pebbletemplates
3 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pebbletemplates 2Pebble Pebble TemplatesJun 5, 2026 Feb 27, 2025 4.8 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafti...Show more |
1Pebbletemplates 1Pebble Templates Nov 21, 2024 Sep 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to...Show more |
1Pebbletemplates 1Pebble Templates Nov 21, 2024 Dec 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.for...Show more |