Code injection issue for java-spring-cloud-stream-template
High severity
GitHub Reviewed
Published
Aug 11, 2021
in
asyncapi/java-spring-cloud-stream-template
•
Updated Feb 1, 2023
Package
Affected versions
<= 0.6.9
Patched versions
0.7.0
Description
Published by the National Vulnerability Database
Aug 11, 2021
Reviewed
Aug 24, 2021
Published to the GitHub Advisory Database
Aug 25, 2021
Last updated
Feb 1, 2023
The following was initially reported by @jonaslagoni:
Given the following command:
ag ./dummy.json @asyncapi/java-spring-cloud-stream-template --force-write --output ./output
With the following AsyncAPI document:
Which changes the following output:
To
References