Security Advisory

CVE-2023-39020

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-07-28 00:00:00
Last updated 2024-10-22 19:43:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.