Description
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Remediation
References
https://github.com/stanfordnlp/CoreNLP/issues/1222
Related Vulnerabilities
CVE-2022-0436 Vulnerability in npm package grunt
CVE-2022-35916 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2020-15366 Vulnerability in maven package org.webjars.bowergithub.epoberezkin:ajv
CVE-2023-37964 Vulnerability in maven package org.jenkins-ci.plugins:elasticbox
CVE-2022-24785 Vulnerability in maven package org.webjars.bower:moment