{"id":"CVE-2021-37694","aliases":["GHSA-xj6r-2jpm-qvxp"],"url":"https://o3.security/vulnerability/CVE-2021-37694","summary":"Code injection issue for java-spring-cloud-stream-template","details":"@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised to update.","published":"2021-08-11T18:15:07.403Z","modified":"2026-07-09T11:24:05.497496Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@asyncapi/java-spring-cloud-stream-template","fixedVersion":"0.7.0"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/asyncapi/java-spring-cloud-stream-template/security/advisories/GHSA-xj6r-2jpm-qvxp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:05.497496Z"}}