Description
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
Remediation
References
https://github.com/code4craft/webmagic/issues/1122
Related Vulnerabilities
CVE-2020-20739 Vulnerability in npm package libvips
CVE-2022-25645 Vulnerability in maven package org.webjars.npm:dset
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-script
CVE-2011-2087 Vulnerability in maven package org.apache.struts:struts2-javatemplates-plugin
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-undertow