PT-2022-12160 · Corenlp · Corenlp

Published

2022-02-23

·

Updated

2022-07-12

·

CVE-2021-44550

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CoreNLP version 4.3.2
Description An issue exists due to incorrect access control in the classifier within NERServlet.java, specifically at lines 158 and 159.
Recommendations For CoreNLP version 4.3.2, consider restricting access to the classifier in NERServlet.java as a temporary workaround until a patch is available.

Exploit

Fix

Special Elements Injection

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44550
GHSA-X2P8-RGFM-QW3V

Affected Products

Corenlp