VYPR

Maven package

com.bstek.uflo/uflo-core

pkg:maven/com.bstek.uflo/uflo-core

Vulnerabilities (1)

  • CVE-2022-25894Jan 25, 2023
    affected <= 2.1.5

    All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.