teerth04 / ticket

Other
0 stars 0 forks source link

Findings for SCA, High, [TheRedHatter/javagoof:todolist-web-struts/pom.xml]:Remote Code Execution #1712

Open armorcodegithubpreprod[bot] opened 4 months ago

armorcodegithubpreprod[bot] commented 4 months ago

Findings for SCA, High, [TheRedHatter/javagoof:todolist-web-struts/pom.xml]:Remote Code Execution

Component Details

Affected versions of this package are vulnerable to Remote Code Execution. When the namespace value is not set for a result defined in underlying xml configurations, and in same time, its upper action(s) configurations have no or wildcard namespace, an attacker may be able to conduct a remote code execution attack. They could also use the opportunity when using a url tag which does not have a value and action set and in same time, its upper action(s) configurations have no or wildcard namespace.

References

Snyk Project Status: Active



armorcodegithubpreprod[bot] commented 4 months ago

Finding [47833756|https://preprod.armorcode.ai/#/findings/257/1167/47833756] is Mitigated
by SYSTEM via ArmorCode Platform