Description
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
Remediation
References
https://github.com/LetianYuan/My-CVE-Public-References/tree/main/opensymphony_oscore
Related Vulnerabilities
CVE-2022-0613 Vulnerability in npm package urijs
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-query-manager
CVE-2022-36922 Vulnerability in maven package org.jenkins-ci.plugins:lucene-search
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-23532 Vulnerability in maven package org.neo4j.procedure:apoc