Description
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
Remediation
References
https://github.com/code4craft/webmagic/issues/1122
Related Vulnerabilities
CVE-2022-24891 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2019-9737 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2020-7743 Vulnerability in maven package org.webjars.npm:mathjs
CVE-2019-10806 Vulnerability in maven package org.webjars.npm:vega-util
CVE-2019-1010266 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash