Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Remediation
References
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c
Related Vulnerabilities
CVE-2017-8028 Vulnerability in maven package org.springframework.ldap:spring-ldap-core
CVE-2018-1335 Vulnerability in maven package org.apache.tika:tika-core
CVE-2018-1000420 Vulnerability in maven package org.jenkins-ci.plugins:mesos
CVE-2019-10372 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth
CVE-2020-1941 Vulnerability in maven package org.apache.activemq:activemq-web-console