Description
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Remediation
References
https://github.com/stanfordnlp/CoreNLP/issues/1222
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars.bower:bootstrap-sass
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2022-22880 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2022-23458 Vulnerability in maven package org.webjars.bowergithub.nhn:tui.grid