Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Remediation
References
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c
Related Vulnerabilities
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2021-40110 Vulnerability in maven package org.apache.james:james-server
CVE-2021-38153 Vulnerability in maven package org.apache.kafka:kafka-clients
CVE-2019-10243 Vulnerability in maven package org.eclipse.kura:target-platform
CVE-2022-0198 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp