Description
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
Remediation
References
https://github.com/LetianYuan/My-CVE-Public-References/tree/main/opensymphony_oscore
Related Vulnerabilities
CVE-2023-34603 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2020-7742 Vulnerability in npm package simpl-schema
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap-sass
CVE-2023-40340 Vulnerability in maven package org.jenkins-ci.plugins:nodejs
CVE-2018-6561 Vulnerability in maven package org.webjars.npm:dijit