Vulnerabilities > CVE-2019-19899 - Missing Authorization vulnerability in Pebbletemplates Pebble Templates 3.1.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |