Description
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
Remediation
References
https://github.com/nacos-group/nacos-spring-project/issues/314
Related Vulnerabilities
CVE-2020-2230 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-11341 Vulnerability in npm package node-sass
CVE-2023-51079 Vulnerability in maven package org.mvel:mvel2
CVE-2021-32854 Vulnerability in maven package org.webjars:textangular
CVE-2019-6286 Vulnerability in maven package org.webjars.npm:node-sass