Description
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
Remediation
References
https://github.com/xCss/Valine/issues/400
Related Vulnerabilities
CVE-2020-7781 Vulnerability in npm package connection-tester
CVE-2021-32640 Vulnerability in npm package ws
CVE-2022-0528 Vulnerability in npm package @uppy/companion
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js
CVE-2023-46731 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui