Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37528
HistoryOct 12, 2022 - 10:01 a.m.

Remote Code Execution (RCE)

2022-10-1210:01:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
remote code execution
commons-jxpath
jxpathcontext.java
xpath expression
java class

commons-jxpath is vulnerable to remote code execution. The vulnerability exists in selectSingleNode function in JXPathContext.java where the attacker can use the xpath expression to load any java class from the classpath which will lead to a code execution.

CPENameOperatorVersion
commons jxpathle1.3
commons jxpathle1.3