Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown
CVE-2020-7712
Disclosure Date: August 30, 2020 (last updated November 08, 2023)
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
0
Attacker Value
Unknown
CVE-2018-1273
Disclosure Date: April 11, 2018 (last updated July 17, 2024)
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
0