Description
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
Remediation
References
https://hackerone.com/reports/660563
Related Vulnerabilities
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-13110 Vulnerability in npm package kerberos
CVE-2020-28277 Vulnerability in maven package org.webjars.npm:dset
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core