{"id":"GHSA-xpv2-8ppj-79hh","summary":"Expression injection in AviatorScript","details":"AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).","aliases":["CVE-2021-41862"],"modified":"2024-02-20T20:15:59.822052Z","published":"2021-10-04T20:14:31Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-10-04T16:58:38Z","nvd_published_at":"2021-10-02T00:15:00Z","cwe_ids":["CWE-74"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41862"},{"type":"WEB","url":"https://github.com/killme2008/aviatorscript/issues/421"},{"type":"PACKAGE","url":"https://github.com/killme2008/aviatorscript"}],"affected":[{"package":{"name":"com.googlecode.aviator:aviator","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.aviator/aviator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.1"},{"last_affected":"5.2.7"}]}],"versions":["5.2.1","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.2.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-xpv2-8ppj-79hh/GHSA-xpv2-8ppj-79hh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}