Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22279
HistoryJan 13, 2020 - 12:54 a.m.

Arbitrary Code Injection

2020-01-1300:54:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.006 Low

EPSS

Percentile

78.2%

hot-formula-parser is vulnerable to arbitrary code injection. The vulnerability exists due to the lack of sanitization of the value of yytext, which is used in the exec command.

0.006 Low

EPSS

Percentile

78.2%