QID 981564
QID 981564: Nodejs (npm) Security Update for devcert-sanscache (GHSA-4gp3-p7ph-x2jr)
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4gp3-p7ph-x2jr for updates pertaining to this vulnerability.
Vendor References
- GHSA-4gp3-p7ph-x2jr -
github.com/advisories/GHSA-4gp3-p7ph-x2jr
CVEs related to QID 981564
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4gp3-p7ph-x2jr | devcert-sanscache |
|