Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22268
HistoryJan 09, 2020 - 4:00 a.m.

Command Injection

2020-01-0904:00:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.004 Low

EPSS

Percentile

73.4%

devcert-sanscache is vulnerable to OS command injection. The commonName parameter used to generate a developer SSL certificate is not validated and sanitized, allowing for command injection as the value is subsequently passed into an exec function.

CPENameOperatorVersion
devcert-sanscachele0.4.6

0.004 Low

EPSS

Percentile

73.4%