RCE via expression value

Description

Users can provide spring expressions as an expression value that could expose data when the rule is executed.

Environment

None

Web links

Activity

Show:
Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Labels

Priority

Zoom

Open Zoom
Created June 10, 2023 at 8:51 PM
Updated March 26, 2024 at 3:23 PM
Resolved June 12, 2023 at 6:25 PM
Zoom