Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Remediation
References
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c
Related Vulnerabilities
CVE-2019-10757 Vulnerability in maven package org.webjars.npm:knex
CVE-2018-3749 Vulnerability in maven package org.webjars.npm:deap
CVE-2017-1000188 Vulnerability in npm package ejs
CVE-2019-16728 Vulnerability in npm package dompurify
CVE-2021-26544 Vulnerability in maven package org.apache.livy:livy-server