Description ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE). Remediation References https://github.com/ff4j/ff4j/issues/624 Related Vulnerabilities CVE-2022-36920 Vulnerability in maven package org.jenkins-ci.plugins:coverity CVE-2020-28441 Vulnerability in npm package conf-cfg-ini CVE-2020-7614 Vulnerability in npm package npm-programmatic CVE-2018-3721 Vulnerability in npm package lodash.mergewith CVE-2023-26129 Vulnerability in npm package bwm-ng Severity Critical Classification CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Exploit Issue Tracking Third Party Advisory NVD-CWE-noinfo