Description
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
Remediation
References
https://github.com/nacos-group/nacos-spring-project/issues/314
Related Vulnerabilities
CVE-2023-22893 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2022-31160 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2019-18954 Vulnerability in npm package pomelo
CVE-2022-1295 Vulnerability in maven package org.webjars.bower:fullpage
CVE-2021-4307 Vulnerability in maven package org.webjars.bower:baobab