blog post (german): <a href="https://www.coronawarn.app/de/blog/2020-11-19-security-update/" rel="nofollow">https://www.coronawarn.app/de/blog/2020-11-19-security-updat...</a><p>the template engine allowed remote code injected throug a country name into the error message