Description
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
Remediation
References
https://github.com/xCss/Valine/issues/400
Related Vulnerabilities
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2022-22885 Vulnerability in maven package cn.hutool:hutool-http
CVE-2020-13934 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2017-16036 Vulnerability in npm package badjs-sourcemap-server
CVE-2021-3859 Vulnerability in maven package io.undertow:undertow-core