VYPR
High severity7.2NVD Advisory· Published Dec 26, 2019· Updated Jun 17, 2026

CVE-2019-19999

CVE-2019-19999

Description

Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Halo Dev/Halo5 versions
    cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:*range: <=1.1.1
    • cpe:2.3:a:halo:halo:1.1.3:beta1:*:*:*:*:*:*
    • cpe:2.3:a:halo:halo:1.1.3:beta2:*:*:*:*:*:*
    • cpe:2.3:a:halo:halo:1.2.0:beta1:*:*:*:*:*:*
    • (no CPE)range: <1.2.0-beta.1
  • Halo/Halodescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.