CVE-2024-22533 is a critical server-side template injection (SSTI) vulnerability affecting xiandafu beetl versions prior to v3.15.12. This flaw allows for arbitrary code execution due to an insufficient blacklist in the DefaultNativeSecurityManager, which can be bypassed when an attacker controls the incoming template. With a CVSS score of 9.8, it presents a severe risk as it can be exploited remotely with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.15.12CPE matchmatch criteria | cpe:2.3:a:xiandafu:beetl:3.15.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.