Description
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
Remediation
References
https://github.com/pf4j/pf4j/issues/536
Related Vulnerabilities
CVE-2016-4055 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2018-5673 Vulnerability in maven package org.apache.geronimo.plugins:dojo
CVE-2019-18350 Vulnerability in npm package ant-design-pro
CVE-2021-21363 Vulnerability in maven package io.swagger:swagger-generator
CVE-2020-12265 Vulnerability in maven package org.webjars:decompress-tar