High severity7.8NVD Advisory· Published May 23, 2023· Updated Jun 17, 2026
CVE-2023-31826
CVE-2023-31826
Description
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.skyscreamer:nevado-jmsMaven | <= 1.3.2 | — |
Affected products
3- cpe:2.3:a:skyscreamer:nevado_jms:1.3.2:*:*:*:*:*:*:*
- Skyscreamer Open Source/Nevado JMSdescription
Patches
Vulnerability mechanics
References
8- novysodope.github.io/2023/04/01/95/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-7gm3-mwjw-j53wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-31826ghsaADVISORY
- nevado.skyscreamer.orgghsaWEB
- nevado.skyscreamer.orgnvdProduct
- github.com/skyscreamer/nevado/issues/121nvdIssue TrackingWEB
- github.com/skyscreamer/nevado/releasesnvdRelease NotesWEB
- novysodope.github.io/2023/04/01/95ghsaWEB
News mentions
0No linked articles in our index yet.