Description
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Remediation
References
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
https://github.com/dromara/hutool/issues/3149
https://github.com/dromara/hutool/releases/tag/5.8.21
https://github.com/google/osv.dev/issues/2195
Related Vulnerabilities
CVE-2023-37263 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2023-1283 Vulnerability in npm package @builder.io/qwik
CVE-2017-16166 Vulnerability in npm package byucslabsix
CVE-2021-43570 Vulnerability in maven package com.starkbank.ellipticcurve:starkbank-ecdsa
CVE-2019-14517 Vulnerability in maven package org.webjars.npm:editor.md