Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Stanford CoreNlp 代码注入漏洞
Vulnerability Description
Stanford CoreNlp是美国Stanford Nlp Group团队的一套开源的,用 Java 编写的自然语言分析工具。 Stanford CoreNlp stanford-parser v3.9.2及之前版本存在安全漏洞,该漏洞源于在组件edu.stanford.nlp.io.getBZip2PipedInputStream中存在代码注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A