Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Remediation
References
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c
Related Vulnerabilities
CVE-2020-8135 Vulnerability in npm package @uppy/companion
CVE-2021-21318 Vulnerability in maven package org.opencastproject:opencast-search-service-impl
CVE-2021-41303 Vulnerability in maven package org.apache.shiro:shiro-core
CVE-2021-21277 Vulnerability in maven package org.webjars.npm:angular-expressions
CVE-2016-8749 Vulnerability in maven package org.apache.camel:camel-jackson