Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2020-15500 Vulnerability in npm package tileserver-gl
CVE-2015-9235 Vulnerability in npm package jsonwebtoken
CVE-2023-45277 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2019-10322 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r4b