[MAVEN:GHSA-859M-2PFX-FWHF] Code injection in oscore

Severity Critical
Affected Packages 1
CVEs 1

oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.

Package Affected Version
pkg:maven/opensymphony/oscore <= 2.2.6
ID
MAVEN:GHSA-859M-2PFX-FWHF
Severity
critical
URL
https://github.com/advisories/GHSA-859m-2pfx-fwhf
Published
2023-07-28T15:30:23
(13 months ago)
Modified
2023-11-05T05:01:00
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/opensymphony/oscore opensymphony oscore <= 2.2.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...