Description
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
Remediation
References
https://github.com/pf4j/pf4j/issues/536
Related Vulnerabilities
CVE-2021-21350 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-25352 Vulnerability in npm package libnested
CVE-2014-0086 Vulnerability in maven package org.richfaces.core:richfaces-core-impl
CVE-2021-43306 Vulnerability in maven package org.webjars.bower:jquery-validation
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api