Description
The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4775
https://github.com/ronomon/opened/commit/7effe011d4fea8fac7f78c00615e0a6e69af68ec
Related Vulnerabilities
CVE-2022-41254 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2022-22143 Vulnerability in npm package convict
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r5
CVE-2023-23936 Vulnerability in npm package undici
CVE-2019-14862 Vulnerability in maven package org.webjars:knockout