Description
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEVCERTSANSCACHE-540926
Related Vulnerabilities
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2021-27906 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo