org.craftercms:crafter-engine@3.1.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.craftercms:crafter-engine package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Arbitrary Command Execution

org.craftercms:crafter-engine is a Crafter Content Delivery Engine.

Affected versions of this package are vulnerable to Arbitrary Command Execution via FreeMarker static methods.

How to fix Arbitrary Command Execution?

Upgrade org.craftercms:crafter-engine to version 3.1.18 or higher.

[3.1.0,3.1.18)
  • M
Improper Output Neutralization for Logs

org.craftercms:crafter-engine is a Crafter Content Delivery Engine.

Affected versions of this package are vulnerable to Improper Output Neutralization for Logs by allowing an anonymous user to craft a URL with text that ends up in the log viewer as is.

How to fix Improper Output Neutralization for Logs?

Upgrade org.craftercms:crafter-engine to version 3.1.18 or higher.

[3.1.0,3.1.18)