Ubuntu Security Notice 6282-1 - Jackson Henry discovered that Velocity Tools incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code.
f5d8dcd9b2dd7d1004589d8aff05de5a8c1772762dcd3a85a846a7c637cfc409
Gentoo Linux Security Advisory 202107-52 - Multiple vulnerabilities have been found in Apache Velocity, the worst of which could result in the arbitrary execution of code. Versions less than 2.3 are affected.
a151f0d600f0a5f670087824f86c2e5c25a0bbb058b16243c5cc875ab0913975