Description
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
Remediation
References
https://hackerone.com/reports/405694
Related Vulnerabilities
CVE-2022-0350 Vulnerability in npm package vditor
CVE-2022-41254 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2016-10538 Vulnerability in npm package cli
CVE-2020-36640 Vulnerability in maven package org.bonitasoft.connectors:bonita-connector-webservice
CVE-2017-16026 Vulnerability in maven package org.webjars:request