Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2020-28437 Vulnerability in npm package heroku-env
CVE-2020-7795 Vulnerability in npm package get-npm-package-version
CVE-2018-17420 Vulnerability in maven package com.zrlog:zrlog
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui