Description
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Remediation
References
https://lists.apache.org/thread/7ctchj24dofgsj9g1rg1245cms9myb34
Related Vulnerabilities
CVE-2021-29620 Vulnerability in maven package com.epam.reportportal:service-api
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-record-serialization-services
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-macro-html
CVE-2023-34036 Vulnerability in maven package org.springframework.hateoas:spring-hateoas
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.13