VDB
Sign up
CRITICAL9.8

GHSA-x487-866m-p8hr

Server-Side Template Injection in Camaleon CMS

Quick fix

GHSA-x487-866m-p8hr — camaleon_cms: upgrade to the fixed version with the command below.

bundle update camaleon_cms

Details

Camaleon CMS prior to 2.7.4 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the `formats` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/camaleon_cms
Introduced in: 0Fixed in: 2.7.4
Fixbundle update camaleon_cms

References