Description
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Remediation
References
https://hackerone.com/reports/341710
Related Vulnerabilities
CVE-2023-49398 Vulnerability in maven package com.jfinal:jfinal
CVE-2013-4152 Vulnerability in maven package org.springframework:spring-oxm
CVE-2023-49487 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-23379 Vulnerability in npm package portkiller
CVE-2022-31023 Vulnerability in maven package com.typesafe.play:play_2.12