Description
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
Remediation
References
https://github.com/skyscreamer/nevado/issues/121
http://nevado.skyscreamer.org/
https://github.com/skyscreamer/nevado/releases
https://novysodope.github.io/2023/04/01/95/
Related Vulnerabilities
CVE-2023-22465 Vulnerability in maven package org.http4s:http4s-core_3
CVE-2020-11021 Vulnerability in npm package @actions/http-client
CVE-2021-41182 Vulnerability in maven package org.webjars:jquery-ui
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-41704 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge