OSV 1.4.0 · github-reviewed · 修改于 2021-12-21 00:57
发布时间
2021-12-21 00:59
GitHub 审查时间
2021-12-21 00:57
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/12/GHSA-qc22-qwm9-j8rx/GHSA-qc22-qwm9-j8rx.json
Versions of npm-groovy-lint prior to 9.1.0 bundle vulnerable versions of the Log4j library which are subject to remote code execution via jndi rendering. As a result npm-groovy-lint prior to 9.1.0 is also vulnerable.