Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2022-0122 Vulnerability in npm package node-forge
CVE-2020-28443 Vulnerability in npm package sonar-wrapper
CVE-2019-12041 Vulnerability in maven package org.webjars.npm:remarkable
CVE-2020-5397 Vulnerability in maven package org.springframework:spring-webflux
CVE-2017-16226 Vulnerability in maven package org.webjars.npm:static-eval