Description
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).
Remediation
References
https://github.com/killme2008/aviatorscript/issues/421
Related Vulnerabilities
CVE-2021-40823 Vulnerability in npm package matrix-js-sdk
CVE-2021-39148 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-23429 Vulnerability in npm package transpile
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2022-41854 Vulnerability in maven package org.yaml:snakeyaml