Description
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
Remediation
References
https://github.com/nacos-group/nacos-spring-project/issues/314
Related Vulnerabilities
CVE-2022-24066 Vulnerability in npm package simple-git
CVE-2016-10735 Vulnerability in maven package li.rudin.mavenjs:bootstrap
CVE-2017-16180 Vulnerability in npm package serverabc
CVE-2016-7103 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash