Critical severity9.8NVD Advisory· Published Feb 2, 2024· Updated Jun 17, 2026
CVE-2024-22533
CVE-2024-22533
Description
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.ibeetl:beetl-coreMaven | < 3.15.13.RELEASE | 3.15.13.RELEASE |
Affected products
3- Beetl/Beetldescription
Patches
Vulnerability mechanics
References
3- gitee.com/xiandafu/beetl/issues/I8RU01nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-9gh8-877r-g477ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-22533ghsaADVISORY
News mentions
0No linked articles in our index yet.