Headline
GHSA-7gm3-mwjw-j53w: Command injection in nevado-jms
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
Command injection in nevado-jms
High severity GitHub Reviewed Published May 23, 2023 to the GitHub Advisory Database • Updated May 23, 2023
Related news
CVE-2023-31826: Is this project still operated by anyone else? · Issue #121 · skyscreamer/nevado
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.