OS Command Injection in devcert-sanscache
Critical severity
GitHub Reviewed
Published
Apr 14, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Apr 14, 2020
Published to the GitHub Advisory Database
Apr 14, 2020
Last updated
Jan 9, 2023
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable
commonName
controlled by user input is used as part of theexec
function without any sanitization.References