Description
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Remediation
References
https://github.com/stanfordnlp/CoreNLP/issues/1222
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2015-8103 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-46498 Vulnerability in npm package @evershop/evershop
CVE-2023-24163 Vulnerability in maven package cn.hutool:hutool-all
CVE-2020-13822 Vulnerability in maven package org.webjars.npm:elliptic