Description
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.
Remediation
References
https://github.com/glazedlists/glazedlists/issues/709
Related Vulnerabilities
CVE-2023-48088 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2023-25572 Vulnerability in npm package react-admin
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2021-31404 Vulnerability in maven package com.vaadin:flow-server
CVE-2021-27568 Vulnerability in maven package net.minidev:json-smart