In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-43466
https://vuldb.com/?id.186365
https://github.com/t…