Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2022-2063 Vulnerability in npm package nocodb
CVE-2023-27096 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2022-31160 Vulnerability in npm package jquery-ui
CVE-2022-36098 Vulnerability in maven package org.xwiki.platform:xwiki-platform-mentions-ui
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons