Skip to content

Remote Code Execution in SCIMono

High
karaimin published GHSA-29q4-gxjq-rx5c Feb 9, 2021

Package

scimono-server

Affected versions

< 0.0.19

Patched versions

0.0.19

Description

Impact

It is possible for attacker to inject and execute java expression and compromising the availability and integrity of the system.

Patches

The issue was fixed on 0.0.19 version

Severity

High

CVE ID

CVE-2021-21479

Weaknesses

No CWEs