Description
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
Remediation
References
https://hackerone.com/reports/390865
Related Vulnerabilities
CVE-2020-2165 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2022-25296 Vulnerability in npm package bodymen
CVE-2015-6584 Vulnerability in maven package org.webjars:datatables
CVE-2020-13934 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2016-4469 Vulnerability in maven package org.apache.archiva:archiva-webapp