• fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    The flaw results from the dangerously exposed /adminui/debug servlet, which evaluates user-supplied OGNL expressions as Java code without requiring authentication or input validation."

    WTF? 😳