Description
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
Remediation
References
https://github.com/LetianYuan/My-CVE-Public-References/tree/main/opensymphony_oscore
Related Vulnerabilities
CVE-2021-37304 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2022-2422 Vulnerability in npm package feathers-sequelize
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2020-28168 Vulnerability in npm package axios
CVE-2019-10747 Vulnerability in maven package org.webjars.npm:set-value