Description
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
Remediation
References
https://github.com/code4craft/webmagic/issues/1122
Related Vulnerabilities
CVE-2022-24197 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2021-23452 Vulnerability in npm package x-assign
CVE-2020-28168 Vulnerability in maven package org.webjars.bower:axios
CVE-2023-34092 Vulnerability in npm package vite
CVE-2023-50100 Vulnerability in maven package com.jfinal:jfinal