Description
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Remediation
References
https://lists.apache.org/thread/7ctchj24dofgsj9g1rg1245cms9myb34
Related Vulnerabilities
CVE-2019-0205 Vulnerability in maven package org.webjars.npm:thrift
CVE-2021-23445 Vulnerability in npm package datatables.net
CVE-2023-33000 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2022-37616 Vulnerability in npm package xmldom
CVE-2023-25194 Vulnerability in maven package org.apache.kafka:kafka-clients