Description
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
Remediation
References
https://github.com/LetianYuan/My-CVE-Public-References/tree/main/opensymphony_oscore
Related Vulnerabilities
CVE-2021-3918 Vulnerability in npm package json-schema
CVE-2023-34093 Vulnerability in npm package @strapi/database
CVE-2022-25844 Vulnerability in npm package angular
CVE-2020-7699 Vulnerability in npm package express-fileupload
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.convertors