Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-web
CVE-2022-27200 Vulnerability in maven package io.jenkins.plugins:folder-auth
CVE-2020-11023 Vulnerability in maven package org.webjars:jquery