Lucene search

K
nodejsAnonymousNODEJS:1713
HistoryMay 18, 2021 - 1:43 a.m.

Injection and Command Injection in devcert

2021-05-1801:43:01
Anonymous
www.npmjs.com
46

0.003 Low

EPSS

Percentile

68.8%

Overview

A command injection vulnerability in the devcert module may lead to remote code execution when users of the module pass untrusted input to the certificateFor function.

Recommendation

Upgrade to version 1.1.2 or later

References

CPENameOperatorVersion
devcertle1.1.1