Description
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Remediation
References
https://github.com/dataease/dataease/issues/2431
Related Vulnerabilities
CVE-2019-12086 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2020-13946 Vulnerability in maven package org.apache.cassandra:cassandra-all
CVE-2021-28169 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2021-3461 Vulnerability in maven package org.keycloak:keycloak-services