Description
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
Remediation
References
http://nevado.skyscreamer.org/
https://github.com/skyscreamer/nevado/issues/121
https://github.com/skyscreamer/nevado/releases
https://novysodope.github.io/2023/04/01/95/
Related Vulnerabilities
CVE-2021-39171 Vulnerability in npm package passport-saml
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2021-32673 Vulnerability in npm package reg-keygen-git-hash-plugin
CVE-2023-42268 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2020-19676 Vulnerability in maven package com.alibaba.nacos:nacos-api