GHSA-8jpx-m2wh-2v34
HIGHCVE-2020-11002A server-side template injection was identified in the self-validating ([@SelfValidating](https://javadoc.io/static/io.dropwizard/dropwizard-project/2.0.3/io/dropwizard/validation/selfvalidating/SelfValidating.html)) feature of dropwizard-validation enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability.
- Affected
- >= 2.0.0, < 2.0.3
- Fixed in
- 2.0.3
- Published
- 2020-04-10
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference