{"id":"CVE-2020-12668","aliases":["GHSA-2hjr-fg6c-v2h6"],"url":"https://o3.security/vulnerability/CVE-2020-12668","summary":"Unauthorized access to Class instance in Jinjava","details":"Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.","published":"2021-02-19T23:15:12.267Z","modified":"2026-07-08T20:58:36.386396Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.hubspot.jinjava:jinjava","fixedVersion":"2.5.4"}],"fix":{"url":"https://github.com/HubSpot/jinjava/pull/426/commits/5dfa5b87318744a4d020b66d5f7747acc36b213b","label":"HubSpot/jinjava#426"},"references":[{"type":"ADVISORY","url":"https://github.com/HubSpot/jinjava/compare/jinjava-2.5.3...jinjava-2.5.4"},{"type":"ADVISORY","url":"https://github.com/HubSpot/jinjava/releases/tag/jinjava-2.5.4"},{"type":"FIX","url":"https://github.com/HubSpot/jinjava/pull/426/commits/5dfa5b87318744a4d020b66d5f7747acc36b213b"},{"type":"FIX","url":"https://github.com/HubSpot/jinjava/pull/435/commits/1b9aaa4b420c58b4a301cf4b7d26207f1c8d1165"},{"type":"EVIDENCE","url":"https://securitylab.github.com/advisories/GHSL-2020-072-hubspot_jinjava"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:58:36.386396Z"}}