Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2020-7626 Vulnerability in npm package karma-mojo
CVE-2019-10792 Vulnerability in npm package bodymen
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2021-26540 Vulnerability in maven package org.webjars.npm:sanitize-html
CVE-2014-6394 Vulnerability in maven package org.webjars.npm:send