Description
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
Remediation
References
https://hackerone.com/reports/863544
Related Vulnerabilities
CVE-2021-21342 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-34614 Vulnerability in maven package cc.plural:jsonij
CVE-2022-37734 Vulnerability in maven package com.graphql-java:graphql-java
CVE-2021-29425 Vulnerability in maven package commons-io:commons-io
CVE-2023-35145 Vulnerability in maven package org.jenkins-ci.plugins:sonargraph-integration