Description
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEVCERTSANSCACHE-540926
Related Vulnerabilities
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-21252 Vulnerability in maven package org.webjars.bower:jquery-validation
CVE-2020-7696 Vulnerability in npm package react-native-fast-image
CVE-2020-28477 Vulnerability in npm package immer
CVE-2023-45280 Vulnerability in maven package org.yamcs:yamcs-core