Critical severity9.8NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-25894
CVE-2022-25894
Description
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.bstek.uflo:uflo-coreMaven | <= 2.1.5 | — |
Affected products
2- com.bstek.uflo/uflo-coredescription
Patches
Vulnerability mechanics
References
7- fmyyy1.github.io/2022/10/23/uflo2rce/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-8m9f-c5p9-wqchghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25894ghsaADVISORY
- security.snyk.io/vuln/SNYK-JAVA-COMBSTEKUFLO-3091112nvdThird Party AdvisoryWEB
- fmyyy1.github.io/2022/10/23/uflo2rceghsaWEB
- github.com/youseries/uflo/blob/b3e198bc6523e5a6ba69edd84ba10e05a3b78726/uflo-core/src/main/java/com/bstek/uflo/expr/impl/ExpressionContextImpl.javaghsaWEB
- github.com/youseries/uflo/blob/b3e198bc6523e5a6ba69edd84ba10e05a3b78726/uflo-core/src/main/java/com/bstek/uflo/expr/impl/ExpressionContextImpl.java%23L126nvdBroken Link
News mentions
0No linked articles in our index yet.