Description
easy-rules-mvel v4.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component MVELRule.
Remediation
References
https://github.com/j-easy/easy-rules/issues/419
Related Vulnerabilities
CVE-2021-23341 Vulnerability in npm package prismjs
CVE-2019-7722 Vulnerability in maven package net.sourceforge.pmd:pmd-core
CVE-2019-1010266 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2021-41189 Vulnerability in maven package org.dspace:dspace-api
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify