Re: CVE-2020-13959: Velocity Tools XSS Vulnerability

Lukasz Lenart <[email protected]> Thu, 18 Mar 2021 08:26:57 +0100
Newsgroups gmane.comp.jakarta.velocity.user
Message-ID <CAMopvkNwRq-4Yst68ELtPL4y4EPn9KQ+9icZT46v=+tnDnfJEA@mail.gmail.com>
czw., 18 mar 2021 o 08:20 Bolz, Michael <[email protected]> napisa=C5=82=
(a):
> Unfortunately we have not the option to easily update to the new artifact=
s.
> As we get Velocity 1.7 as a transitive dependency.
> Even if we exclude the old 1.7 version and add the 2.3 version we expect =
problems based on the behaviour and API changes mentioned [1].
>
> Hence, we try to understand if Velocity 1.7 is affected by the CVE-2020-1=
3959 vulnerability.
> At least currently it looks like it is affected, as the 2.x and 1.x has t=
he same codebase (as far as I understand).

I would report this issue in the project that depends on the old
Velocity version, maybe they will fix it or in the worst case scenario
you will have to prepare a PR - hopefully they will merge it quickly
:)


Regards
--=20
=C5=81ukasz
+ 48 606 323 122 http://www.lenart.org.pl/