Skip to content

[GHSA-862q-5rrg-cc9p] Improper Control of Generation of Code ('Code Injection')...#8007

Closed
lohitkolluri wants to merge 1 commit into
lohitkolluri/advisory-improvement-8007from
lohitkolluri-GHSA-862q-5rrg-cc9p
Closed

[GHSA-862q-5rrg-cc9p] Improper Control of Generation of Code ('Code Injection')...#8007
lohitkolluri wants to merge 1 commit into
lohitkolluri/advisory-improvement-8007from
lohitkolluri-GHSA-862q-5rrg-cc9p

Conversation

@lohitkolluri

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • Description
  • Severity
  • Summary

Comments
CVSS v3.1 score and vector from Tenable/NVD at https://www.tenable.com/cve/CVE-2026-50223. Affected versions from Apache OFBiz security advisory and Tenable. Maven package org.apache.ofbiz:ofbiz from Apache OFBiz Maven Central artifacts.

Copilot stopped work on behalf of lohitkolluri due to an error June 11, 2026 12:24
@github-actions github-actions Bot changed the base branch from main to lohitkolluri/advisory-improvement-8007 June 11, 2026 12:25
@JonathanLEvans

Copy link
Copy Markdown

Hi @lohitkolluri,

Could you provide a link to where you found org.apache.ofbiz:ofbiz on Maven Central?

@lohitkolluri

Copy link
Copy Markdown
Author

I checked and org.apache.ofbiz:ofbiz isn't actually on Maven Central, looks like I inferred it from the Java package namespace. I'll close this PR since the Maven reference doesn't hold up.

@github-actions github-actions Bot deleted the lohitkolluri-GHSA-862q-5rrg-cc9p branch June 13, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants