Description
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Remediation
References
https://github.com/stanfordnlp/CoreNLP/issues/1222
Related Vulnerabilities
CVE-2022-0144 Vulnerability in npm package shelljs
CVE-2020-7677 Vulnerability in maven package org.webjars.npm:thenify
CVE-2022-23082 Vulnerability in maven package io.whitesource:curekit
CVE-2021-25912 Vulnerability in npm package dotty
CVE-2023-26139 Vulnerability in npm package underscore-keypath