Description
An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.
Remediation
References
https://github.com/shenzhim/aaptjs/issues/2
Related Vulnerabilities
CVE-2022-39312 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2015-6584 Vulnerability in npm package datatables
CVE-2021-39152 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-7676 Vulnerability in maven package org.webjars.npm:angular
CVE-2022-35949 Vulnerability in maven package org.webjars.npm:undici