Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2017-16008 Vulnerability in maven package org.webjars.bower:i18next
CVE-2021-43788 Vulnerability in npm package nodebb
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug-code-gen
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream