CVE-2023-38286: Codecentric Spring Boot Admin
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.
Affected products
- Codecentric Spring Boot Admin: up to and including 3.1.0
- Thymeleaf Thymeleaf: up to and including 3.1.1
Published 2023-07-14. Last modified 2026-06-17.