VDB
Sign up
CRITICAL9.8

GHSA-4gp3-p7ph-x2jr

OS Command Injection in devcert-sanscache

Quick fix

GHSA-4gp3-p7ph-x2jr — devcert-sanscache: upgrade to the fixed version with the command below.

npm install devcert-sanscache@0.4.7

Details

devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/devcert-sanscache
Introduced in: 0Fixed in: 0.4.7
Fixnpm install devcert-sanscache@0.4.7

References