Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2023-29566 Vulnerability in npm package dawnsparks-node-tesseract
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap-sass
CVE-2021-42228 Vulnerability in npm package kindeditor
CVE-2023-35153 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui
CVE-2020-2232 Vulnerability in maven package org.jenkins-ci.plugins:email-ext