Description
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
Remediation
References
https://github.com/nacos-group/nacos-spring-project/issues/314
Related Vulnerabilities
CVE-2022-24725 Vulnerability in npm package shescape
CVE-2022-22984 Vulnerability in npm package snyk
CVE-2020-36179 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-15123 Vulnerability in npm package codecov
CVE-2021-21361 Vulnerability in maven package com.bmuschko:gradle-vagrant-plugin