CVE-2020-13936 — velocity-engine-parent
HIGHCVE-2020-13936 is a high-severity (CVSS 8.8) vulnerability in org.apache.velocity:velocity-engine-parent. EPSS puts its 30-day exploitation probability at 22.7% (98th percentile). A fix is available for org.apache.velocity:velocity-engine-parent — see the affected versions and patch details below.
Sandbox Bypass in Apache Velocity Engine
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2020-13936 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,738 CVEs with a current EPSS score, this one falls in the 10–50% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
org.apache.velocity:velocity-engine-parent☕org.apache.velocity:velocityReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | org.apache.velocity:velocity-engine-parent | all versions | 2.3org.apache.velocity:velocity-engine-parent:2.3 |
| ☕Maven | org.apache.velocity:velocity | all versions | No fix |
Affected Products
velocity engineapachewss4japachedebian linuxdebianbanking deposits and lines of credit servicingoraclebanking enterprise default managementoraclebanking loans servicingoracleDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.apache.velocity:velocity-engine-parent, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update org.apache.velocity:velocity-engine-parent to 2.3 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2020-13936 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
OpenShift Container Platform (OCP) openshift-logging/elasticsearch6-rhel8 container does contain a vulnerable version of velocity. The references to the library only occur in the x-pack component which is an enterprise-only feature of Elasticsearch - hence it has been marked as wontfix as this time and may be fixed in…
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat EAP-XP 2.0.0 via EAP 7.3.x base | velocity | RHSA-2021:2755 |
| Red Hat EAP-XP via EAP 7.3.x base | velocity | RHSA-2021:2210 |
| Red Hat Fuse 7.9 | velocity | RHSA-2021:3140 |
| Red Hat Integration | velocity | RHSA-2021:4918 |
| Red Hat Integration Camel Quarkus 2 | see advisory | RHSA-2021:4767 |
| Red Hat JBoss Enterprise Application Platform | org.apache.velocity/velocity-engine-core:2.3.0.redhat-00001 | RHSA-2021:3660 |
| Red Hat JBoss Enterprise Application Platform 7 | velocity | RHSA-2021:2051 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7 | RHSA-2025:1746 |
Frequently Asked Questions
Is CVE-2020-13936 in your dependencies?
Find it across Maven, including transitive dependencies.