davewasmer/devcert
Releases35
Frequency3 months 4 days
Last Release
Stars1.31K
Local HTTPS development made easy
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 1.2.1 | 5.9 MEDIUM | 5 MEDIUM | ||
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method | ||||
| = 1.1.0, < 1.1.2 | 9.8 CRITICAL | 7.5 HIGH | ||
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function. | ||||