Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Remediation
References
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c
Related Vulnerabilities
CVE-2023-26486 Vulnerability in npm package vega-functions
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2017-16222 Vulnerability in npm package elding
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-standalone
CVE-2023-3432 Vulnerability in maven package net.sourceforge.plantuml:plantuml