CVE-2020-13936
published 2021-03-10CVE-2020-13936: An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account…
PriorityP271high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
22.71%
97.5th percentile
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | velocity_engine | < 2.3 | 2.3 |
| apache | velocity_engine | >= 0 < 1.7-6 | 1.7-6 |
| apache | velocity_engine | >= 0 < 1.7-6 | 1.7-6 |
| apache | velocity_engine | >= 0 < 1.7-6 | 1.7-6 |
| apache | velocity_engine | >= 0 < 1.7-6 | 1.7-6 |
| apache | wss4j | — | — |
| apache_software_foundation | apache_velocity_engine | Apache Velocity Engine – 2.2 | — |
| debian | debian_linux | — | — |
| debian | velocity | < velocity 1.7-6 (bookworm) | velocity 1.7-6 (bookworm) |
| oracle | banking_deposits_and_lines_of_credit_servicing | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | 2.3.0 – 2.4.1 | — |
| oracle | banking_loans_servicing | — | — |
| oracle | banking_party_management | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | 2.3.0 – 2.4.1 | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | hospitality_token_proxy_service | — | — |
| oracle | retail_integration_bus | — | — |
| oracle | retail_order_broker | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Server-Side Template Injection (SSTI) attempts targeting Apache Velocity Engine — look for Velocity template syntax (e.g., #set, $class, #evaluate directives) in user-controlled input fields, uploaded files, or HTTP request bodies that are rendered by the Velocity engine. ↗
- →Monitor for arbitrary Java code execution or OS command execution originating from the Servlet container process — unexpected child processes spawned by the Java servlet container (e.g., Tomcat, JBoss) may indicate successful exploitation of CVE-2020-13936. ↗
- →Flag applications running Apache Velocity Engine versions up to and including 2.2 that expose template upload or modification functionality to untrusted users — these are the directly vulnerable attack surface. ↗
- →CVE-2020-13936 is associated with the 'Apache Velocity SSTI' technique (HTB challenge 'Labyrinth Linguist') — alert on Velocity-specific SSTI payloads in web application inputs. ↗
- ·Red Hat Enterprise Linux 6 ships a version of Velocity that does NOT contain the vulnerable code and is not affected. ↗
- ·Red Hat Enterprise Linux 7's Velocity is a vulnerable version but is used as a dependency for IdM/ipa which does not invoke the vulnerable functionality — rated Moderate. ↗
- ·Red Hat Enterprise Linux 8's pki-deps:10.6 Velocity is a vulnerable version but the vulnerable code path is not exercised by pki — rated Low. ↗
- ·OpenShift Container Platform elasticsearch6 container contains vulnerable Velocity but the references only occur in the x-pack enterprise-only component — marked wontfix. ↗
- ·Oracle advisory notes this CVE is not remotely exploitable without prior authenticated/privileged access — attacker must already be able to modify templates. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Studio (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2025-07-15·CVSS 7.3
CVE-2020-13936 [HIGH] Oracle Oracle GoldenGate Risk Matrix: GoldenGate Studio (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Studio (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 7.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2025-04-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: Multiple
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Ubuntu
Velocity Engine vulnerability
vendor_ubuntu·2023-08-10
CVE-2020-13936 Velocity Engine vulnerability
Title: Velocity Engine vulnerability
Summary: Velocity Engine could be made to run arbitrary code if it opened a specially
crafted file.
Alvaro Munoz discovered that Velocity Engine incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: IDM - Authentication (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2023-07-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: IDM - Authentication (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Financial Services Applications Risk Matrix: IDM - Authentication (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2023-04-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Utilities Applications Risk Matrix: General (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Utilities Applications Risk Matrix: General (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2022-10-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Communications Risk Matrix: Platform (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: TL1 Cartridge (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2022-04-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Communications Applications Risk Matrix: TL1 Cartridge (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Communications Applications Risk Matrix: TL1 Cartridge (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Apache Velocity Engine) — CVE-2020-13936
vendor_oracle·2022-01-15·CVSS 8.8
CVE-2020-13936 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (Apache Velocity Engine) — CVE-2020-13936
Oracle Oracle Communications Risk Matrix: Policy (Apache Velocity Engine) vulnerability
CVE: CVE-2020-13936
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
velocity: arbitrary code execution when attacker is able to modify templates
vendor_redhat·2021-03-09·CVSS 8.8
CVE-2020-13936 [HIGH] CWE-94 velocity: arbitrary code execution when attacker is able to modify templates
velocity: arbitrary code execution when attacker is able to modify templates
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
A flaw was found in velocity. An attacker, able to modify Velocity templates, may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: OpenShift Container Platform (OCP) openshift-l
Debian
CVE-2020-13936: velocity - An attacker that is able to modify Velocity templates may execute arbitrary Java...
vendor_debian·2020·CVSS 8.8
CVE-2020-13936 [HIGH] CVE-2020-13936: velocity - An attacker that is able to modify Velocity templates may execute arbitrary Java...
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
Scope: local
bookworm: resolved (fixed in 1.7-6)
bullseye: resolved (fixed in 1.7-6)
forky: resolved (fixed in 1.7-6)
sid: resolved (fixed in 1.7-6)
trixie: resolved (fixed in 1.7-6)
GHSA
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
ghsa·2026-07-08
CVE-2026-49832 [HIGH] CWE-94 DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
## Overview
Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator credentials in order to perform the attack.
This attack is related to the path traversal attack identified in [GHSA-9qm4-rh6w-pq5x](https://github.com/DSpace/DSpace/security/advisories/GHSA-9qm4-rh6w-pq5x) as it was the impactful part of the "proof-of-concept" attack chain.
## Impact
When chained with the LDN Path Traversal Attack identified in [GHSA-9qm4-rh6w-pq5x](https://github.com/DSpace/D
OSV
Sandbox Bypass in Apache Velocity Engine
osv·2022-01-06
CVE-2020-13936 [HIGH] Sandbox Bypass in Apache Velocity Engine
Sandbox Bypass in Apache Velocity Engine
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
GHSA
Sandbox Bypass in Apache Velocity Engine
ghsa·2022-01-06
CVE-2020-13936 [HIGH] CWE-20 Sandbox Bypass in Apache Velocity Engine
Sandbox Bypass in Apache Velocity Engine
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
OSV
CVE-2020-13936: An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the
osv·2021-03-10·CVSS 8.8
CVE-2020-13936 [HIGH] CVE-2020-13936: An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-13936 velocity: arbitrary code execution when attacker is able to modify templates
bugzilla·2021-03-10·CVSS 8.8
CVE-2020-13936 [HIGH] CVE-2020-13936 velocity: arbitrary code execution when attacker is able to modify templates
CVE-2020-13936 velocity: arbitrary code execution when attacker is able to modify templates
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
References:
https://lists.apache.org/thread.html/r01043f584cbd47959fabe18fff64de940f81a65024bb8dddbda31d9a%40%3Cuser.velocity.apache.org%3E
http://www.openwall.com/lists/oss-security/2021/03/10/1
Discussion:
Created eclipse tracking bugs for this issue:
Affects: fedora-all [bug 1937442]
Created velocity tracking bugs for this issue:
Affects: fedora-all [bug 1937441
CTF
web / README
ctf_writeups
web / README
---
layout: default
title: "Web"
parent: Challenges
nav_order: 1
permalink: /challenges/web/
---
## Web Challenges
| # | Challenge | Difficulty | Key Techniques | Writeup |
|---|-----------|-----------|----------------|---------|
| 1 | Trapped Source | Very Easy | Client-Side Source Analysis | [7Rocky](https://7rocky.github.io/en/ctf/htb-challenges/web/trapped-source/) |
| 2 | Templated | Very Easy | Jinja2 SSTI | [7Rocky](https://7rocky.github.io/en/ctf/htb-challenges/web/templated/) |
| 3 | Flag Command | Very Easy | API Exploitation, Command Injection | [7Rocky](https://7rocky.github.io/en/ctf/htb-challenges/web/flag-command/) |
| 4 | looking glass | Easy | SSTI, Command Injection | [7Rocky](https://7rocky.github.io/en/ctf/htb-challenges/web/looking-glass/) |
| 5 | Gunship | Easy | Pr
CTF
README
ctf_writeups
README
# HackTheBox Challenges - Comprehensive Index
> Master index of all HackTheBox challenges organized by category with writeup links, difficulty ratings, and key techniques.
---
## Categories Overview
| Category | Count | Path | Key Skills |
|----------|-------|------|------------|
| [Web](#web-challenges) | 75+ | [`challenges/web/`](web/) | XSS, SQLi, SSTI, SSRF, Deserialization, JWT |
| [Crypto](#crypto-challenges) | 93+ | [`challenges/crypto/`](crypto/) | RSA, AES, ECC, Padding Oracle, Custom Ciphers |
| [Forensics](#forensics-challenges) | 33+ | [`challenges/forensics/`](forensics/) | Memory, Disk, Network, Log Analysis |
| [Reversing](#reversing-challenges) | 44+ | [`challenges/reversing/`](reversing/) | x86/x64, ARM, .NET, Java, Obfuscation |
| [Pwn](#pwn-challenges) | 61+ | [`chal
http://www.openwall.com/lists/oss-security/2021/03/10/1https://lists.apache.org/thread.html/r01043f584cbd47959fabe18fff64de940f81a65024bb8dddbda31d9a%40%3Cuser.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r01043f584cbd47959fabe18fff64de940f81a65024bb8dddbda31d9a%40%3Cuser.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r0bc98e9cd080b4a13b905c571b9bed87e1a0878d44dbf21487c6cca4%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r17cb932fab14801b14e5b97a7f05192f4f366ef260c10d4a8dba8ac9%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r293284c6806c73f51098001ea86a14271c39f72cd76af9e946d9d9ad%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r39de20c7e9c808b1f96790875d33e58c9c0aabb44fd9227e7b3dc5da%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r3ea4c4c908505b20a4c268330dfe7188b90c84dcf777728d02068ae6%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r4cd59453b65d4ac290fcb3b71fdf32b4f1f8989025e89558deb5a245%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r52a5129df402352adc34d052bab9234c8ef63596306506a89fdc7328%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r7f209b837217d2a0fe5977fb692e7f15d37fa5de8214bcdc4c21d9a7%40%3Ccommits.turbine.apache.org%3Ehttps://lists.apache.org/thread.html/r9dc2505651788ac668299774d9e7af4dc616be2f56fdc684d1170882%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb042f3b0090e419cc9f5a3d32cf0baff283ccd6fcb1caea61915d6b6%40%3Ccommits.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/rbee7270556f4172322936b5ecc9fabf0c09f00d4fa56c9de1963c340%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/rd2a89e17e8a9b451ce655f1a34117752ea1d18a22ce580d8baa824fd%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rd7e865c87f9043c21d9c1fd9d4df866061d9a08cfc322771160d8058%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/re641197d204765130618086238c73dd2ce5a3f94b33785b587d72726%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/re8e7482fe54d289fc0229e61cc64947b63b12c3c312e9f25bf6f3b8c%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/reab5978b54a9f4c078402161e30a89c42807b198814acadbe6c862c7%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/rf7d369de88dc88a1347006a3323b3746d849234db40a8edfd5ebc436%40%3Cdev.ws.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00019.htmlhttps://security.gentoo.org/glsa/202107-52https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2021/03/10/1https://lists.apache.org/thread.html/r01043f584cbd47959fabe18fff64de940f81a65024bb8dddbda31d9a%40%3Cuser.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r01043f584cbd47959fabe18fff64de940f81a65024bb8dddbda31d9a%40%3Cuser.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/r0bc98e9cd080b4a13b905c571b9bed87e1a0878d44dbf21487c6cca4%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r17cb932fab14801b14e5b97a7f05192f4f366ef260c10d4a8dba8ac9%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r293284c6806c73f51098001ea86a14271c39f72cd76af9e946d9d9ad%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r39de20c7e9c808b1f96790875d33e58c9c0aabb44fd9227e7b3dc5da%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r3ea4c4c908505b20a4c268330dfe7188b90c84dcf777728d02068ae6%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r4cd59453b65d4ac290fcb3b71fdf32b4f1f8989025e89558deb5a245%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/r52a5129df402352adc34d052bab9234c8ef63596306506a89fdc7328%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r7f209b837217d2a0fe5977fb692e7f15d37fa5de8214bcdc4c21d9a7%40%3Ccommits.turbine.apache.org%3Ehttps://lists.apache.org/thread.html/r9dc2505651788ac668299774d9e7af4dc616be2f56fdc684d1170882%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb042f3b0090e419cc9f5a3d32cf0baff283ccd6fcb1caea61915d6b6%40%3Ccommits.velocity.apache.org%3Ehttps://lists.apache.org/thread.html/rbee7270556f4172322936b5ecc9fabf0c09f00d4fa56c9de1963c340%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/rd2a89e17e8a9b451ce655f1a34117752ea1d18a22ce580d8baa824fd%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rd7e865c87f9043c21d9c1fd9d4df866061d9a08cfc322771160d8058%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/re641197d204765130618086238c73dd2ce5a3f94b33785b587d72726%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/re8e7482fe54d289fc0229e61cc64947b63b12c3c312e9f25bf6f3b8c%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/reab5978b54a9f4c078402161e30a89c42807b198814acadbe6c862c7%40%3Cdev.ws.apache.org%3Ehttps://lists.apache.org/thread.html/rf7d369de88dc88a1347006a3323b3746d849234db40a8edfd5ebc436%40%3Cdev.ws.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00019.htmlhttps://security.gentoo.org/glsa/202107-52https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-03-10
Published