Description
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
Remediation
References
https://github.com/mysticatea/eslint-utils/security/advisories/GHSA-3gx7-xhv7-5mx3
Related Vulnerabilities
CVE-2020-2283 Vulnerability in maven package org.jenkins-ci.plugins:liquibase-runner
CVE-2022-24614 Vulnerability in maven package com.drewnoakes:metadata-extractor
CVE-2019-10172 Vulnerability in maven package org.codehaus.jackson:jackson-mapper-asl
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf