An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-velocityamazon-linux-ami-2-upgrade-velocity-demoamazon-linux-ami-2-upgrade-velocity-javadocamazon-linux-ami-2-upgrade-velocity-manual | Jul 19, 2021 | Mar 10, 2021 | |
| Atlassian Bitbucket | atlassian-bitbucket-upgrade-latest | Nov 14, 2024 | Oct 17, 2023 | |
| Debian | debian-upgrade-velocity | Mar 19, 2021 | Mar 10, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-java-velocity | Jul 26, 2021 | Mar 10, 2021 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-velocity | Sep 16, 2021 | Mar 10, 2021 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-velocity | Apr 30, 2021 | Mar 10, 2021 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-velocity | Jul 19, 2021 | Mar 10, 2021 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-velocity | Jun 28, 2021 | Mar 10, 2021 | |
| Oracle Weblogic | oracle-weblogic-apr-2025-cpu-12_2_1_4_0oracle-weblogic-apr-2025-cpu-14_1_1_0_0 | Oct 15, 2025 | Apr 15, 2025 | |
| Red Hat Jboss Eap | red-hat-jboss-eap-upgrade-latest | Sep 19, 2024 | Mar 9, 2021 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 10, 2021 | |
| Suse | — | suse-upgrade-velocitysuse-upgrade-velocity-demosuse-upgrade-velocity-javadocsuse-upgrade-velocity-manual | Mar 20, 2021 | Mar 10, 2021 |
| Ubuntu | ubuntu-pro-upgrade-velocityubuntu-upgrade-velocity | Aug 11, 2023 | Mar 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub