Description
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CDMESSENGER-571493
Related Vulnerabilities
CVE-2022-28158 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2018-3721 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2022-45400 Vulnerability in maven package org.jvnet.hudson.plugins:japex
CVE-2022-24881 Vulnerability in maven package com.hccake:ballcat-codegen