Description
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Remediation
References
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
https://github.com/dromara/hutool/issues/3149
https://github.com/dromara/hutool/releases/tag/5.8.21
https://github.com/google/osv.dev/issues/2195
Related Vulnerabilities
CVE-2020-8158 Vulnerability in npm package typeorm
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-broker
CVE-2020-15366 Vulnerability in maven package org.webjars.bowergithub.epoberezkin:ajv
CVE-2022-24373 Vulnerability in npm package react-native-reanimated