Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox
CVE-2023-42277 Vulnerability in maven package cn.hutool:hutool-core
CVE-2020-29204 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2021-23328 Vulnerability in npm package iniparserjs
CVE-2021-21307 Vulnerability in maven package org.lucee:lucee