Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2023-29211 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http
CVE-2022-1233 Vulnerability in maven package org.webjars.npm:urijs
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2019-18798 Vulnerability in maven package org.webjars.npm:node-sass