Description
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
Remediation
References
http://nevado.skyscreamer.org/
https://github.com/skyscreamer/nevado/issues/121
https://github.com/skyscreamer/nevado/releases
https://novysodope.github.io/2023/04/01/95/
Related Vulnerabilities
CVE-2021-26540 Vulnerability in maven package org.webjars.npm:sanitize-html
CVE-2022-36437 Vulnerability in maven package com.hazelcast.jet:hazelcast-jet-enterprise
CVE-2022-35923 Vulnerability in npm package v8n
CVE-2020-7640 Vulnerability in npm package pixl-class
CVE-2020-35211 Vulnerability in maven package io.atomix:atomix