漏洞描述
A Server Side Template Injection in changedetection.io caused by usage of unsafe functions of Jinja2 allows Remote Command Execution on the server host.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2024-32651↗github.comhttps://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-4r7v-whpg-8rx3↗github.comhttps://github.com/dgtlmoon/changedetection.io/releases/tag/0.45.21↗www.onsecurity.iohttps://www.onsecurity.io/blog/server-side-template-injection-with-jinja2↗