Description
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
Remediation
References
https://github.com/JinYiTong/CVE-Req/blob/main/ureport2/ureport2-console.md
https://snyk.io/vuln/SNYK-JAVA-COMBSTEKUREPORT-2322018
Related Vulnerabilities
CVE-2023-24187 Vulnerability in maven package com.bstek.ureport:ureport2-core
CVE-2022-25883 Vulnerability in maven package org.webjars.npm:semver
CVE-2022-41642 Vulnerability in npm package nadesiko3
CVE-2022-24433 Vulnerability in maven package org.webjars.npm:simple-git
CVE-2023-27162 Vulnerability in maven package org.openapitools:openapi-generator-project