Description
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-HEROKUENV-1050432
Related Vulnerabilities
CVE-2021-43788 Vulnerability in npm package nodebb
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.convertors
CVE-2021-21193 Vulnerability in npm package electron
CVE-2022-39259 Vulnerability in maven package io.github.skylot:jadx-plugins-api
CVE-2022-36083 Vulnerability in npm package jose-browser-runtime