Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25692
HistoryJun 16, 2020 - 8:17 a.m.

OS Command Injection

2020-06-1608:17:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

68.8%

devcert is vulnerable to remote code execution (RCE). It is possible because it does not validate the user-provided string-concatenated input to the run() command in utils.js, which is subsequently passed to execSync, leading to execution of malicious commands.

CPENameOperatorVersion
devcertle1.1.0

0.003 Low

EPSS

Percentile

68.8%