Description
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
Remediation
References
https://hackerone.com/reports/863544
Related Vulnerabilities
CVE-2022-1233 Vulnerability in maven package org.webjars.bower:urijs
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-26256 Vulnerability in npm package fast-csv
CVE-2020-7709 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2020-24660 Vulnerability in npm package node-lemonldap-ng-handler