Description
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4782
Related Vulnerabilities
CVE-2022-45207 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2022-25869 Vulnerability in maven package org.webjars.npm:angular
CVE-2022-2216 Vulnerability in npm package parse-url
CVE-2020-7739 Vulnerability in npm package phantomjs-seo
CVE-2022-29237 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl