Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-7gm3-mwjw-j53w: Command injection in nevado-jms

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.

ghsa
#git

Command injection in nevado-jms

High severity GitHub Reviewed Published May 23, 2023 to the GitHub Advisory Database • Updated May 23, 2023

Related news

CVE-2023-31826: Is this project still operated by anyone else? · Issue #121 · skyscreamer/nevado

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.