Description
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
Remediation
References
https://hackerone.com/reports/863544
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-logparser
CVE-2023-35839 Vulnerability in maven package org.noear:solon.serialization.hessian
CVE-2022-43432 Vulnerability in maven package org.jenkins-ci.plugins:xframium
CVE-2018-8815 Vulnerability in maven package org.opencms:opencms-core