Description
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0927 | A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function. |
Github GHSA |
GHSA-4228-7qvx-f4rq | Injection and Command Injection in devcert |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/863544 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:56:26.952Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8186
No data.
Status : Modified
Published: 2020-07-10T16:15:11.843
Modified: 2024-11-21T05:38:27.743
Link: CVE-2020-8186
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA