cbcvebase.
CVE-2020-13936
published 2021-03-10

CVE-2020-13936: An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account…

PriorityP271high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
22.71%
97.5th percentile
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
apachevelocity_engine< 2.32.3
apachevelocity_engine>= 0 < 1.7-61.7-6
apachevelocity_engine>= 0 < 1.7-61.7-6
apachevelocity_engine>= 0 < 1.7-61.7-6
apachevelocity_engine>= 0 < 1.7-61.7-6
apachewss4j
apache_software_foundationapache_velocity_engineApache Velocity Engine – 2.2
debiandebian_linux
debianvelocity< velocity 1.7-6 (bookworm)velocity 1.7-6 (bookworm)
oraclebanking_deposits_and_lines_of_credit_servicing
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management2.3.0 – 2.4.1
oraclebanking_loans_servicing
oraclebanking_party_management
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform2.3.0 – 2.4.1
oraclecommunications_cloud_native_core_policy
oraclecommunications_network_integrity
oraclehospitality_token_proxy_service
oracleretail_integration_bus
oracleretail_order_broker

Detection & IOCsextracted from sources · hover to see the quote

  • Detect Server-Side Template Injection (SSTI) attempts targeting Apache Velocity Engine — look for Velocity template syntax (e.g., #set, $class, #evaluate directives) in user-controlled input fields, uploaded files, or HTTP request bodies that are rendered by the Velocity engine.
  • Monitor for arbitrary Java code execution or OS command execution originating from the Servlet container process — unexpected child processes spawned by the Java servlet container (e.g., Tomcat, JBoss) may indicate successful exploitation of CVE-2020-13936.
  • Flag applications running Apache Velocity Engine versions up to and including 2.2 that expose template upload or modification functionality to untrusted users — these are the directly vulnerable attack surface.
  • CVE-2020-13936 is associated with the 'Apache Velocity SSTI' technique (HTB challenge 'Labyrinth Linguist') — alert on Velocity-specific SSTI payloads in web application inputs.
  • ·Red Hat Enterprise Linux 6 ships a version of Velocity that does NOT contain the vulnerable code and is not affected.
  • ·Red Hat Enterprise Linux 7's Velocity is a vulnerable version but is used as a dependency for IdM/ipa which does not invoke the vulnerable functionality — rated Moderate.
  • ·Red Hat Enterprise Linux 8's pki-deps:10.6 Velocity is a vulnerable version but the vulnerable code path is not exercised by pki — rated Low.
  • ·OpenShift Container Platform elasticsearch6 container contains vulnerable Velocity but the references only occur in the x-pack enterprise-only component — marked wontfix.
  • ·Oracle advisory notes this CVE is not remotely exploitable without prior authenticated/privileged access — attacker must already be able to modify templates.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.