Site icon API Security Blog

OpenAM<=15.0.3 FreeMarker – Template Injection

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user…Read More

Exit mobile version