{"id":"CVE-2022-24881","aliases":["GHSA-fv3m-xhqw-9m79"],"url":"https://o3.security/vulnerability/CVE-2022-24881","summary":"Command Injection in Ballcat Codegen","details":"### Impact\nBallcat Codegen provides the function of online editing code to generate templates.\nIn version < 1.0.0.beta.2, since Velocity and freemarker templates are introduced but input verification is not done, attackers can implement remote code execution through malicious code injection of the template engine.\n\n### Patches\nThe fault is rectified and needs to be upgraded to the latest version.","published":"2022-04-26T16:06:21Z","modified":"2026-08-12T13:00:03.655470Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.hccake:ballcat-codegen","fixedVersion":"1.0.0.beta.2"}],"fix":{"url":"https://github.com/ballcat-projects/ballcat-codegen/commit/84a7cb38daf0295b93aba21d562ec627e4eb463b","label":"ballcat-projects/ballcat-codegen@84a7cb3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24881.json"},{"type":"ADVISORY","url":"https://github.com/ballcat-projects/ballcat-codegen/security/advisories/GHSA-fv3m-xhqw-9m79"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24881"},{"type":"REPORT","url":"https://github.com/ballcat-projects/ballcat-codegen/issues/5"},{"type":"FIX","url":"https://github.com/ballcat-projects/ballcat-codegen/commit/84a7cb38daf0295b93aba21d562ec627e4eb463b"},{"type":"PACKAGE","url":"https://github.com/ballcat-projects/ballcat-codegen"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:00:03.655470Z"}}