Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
| Software | From | Fixed in |
|---|---|---|
| halo / halo | 1.2.0-beta1 | 1.2.0-beta1.x |
| halo / halo | 1.1.3-beta1 | 1.1.3-beta1.x |
| halo / halo | 1.1.3-beta2 | 1.1.3-beta2.x |
| halo / halo | - | 1.1.1.x |