Description
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
Remediation
References
https://github.com/noear/solon/compare/v2.3.2...v2.3.3
https://github.com/noear/solon/issues/145
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2019-19935 Vulnerability in npm package froala-editor
CVE-2022-25857 Vulnerability in maven package org.yaml:snakeyaml
CVE-2012-0392 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2020-28168 Vulnerability in maven package org.webjars.bowergithub.axios:axios