Description
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
Remediation
References
https://hackerone.com/reports/390865
Related Vulnerabilities
CVE-2021-32641 Vulnerability in npm package auth0-lock
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2023-24789 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore