Description
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Remediation
References
https://github.com/stanfordnlp/CoreNLP/issues/1222
Related Vulnerabilities
CVE-2023-39022 Vulnerability in maven package opensymphony:oscore
CVE-2022-40152 Vulnerability in maven package com.fasterxml.woodstox:woodstox-core
CVE-2023-43643 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash
CVE-2023-0674 Vulnerability in maven package com.xuxueli:xxl-job-core