Description
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-HEROKUENV-1050432
Related Vulnerabilities
CVE-2019-9155 Vulnerability in npm package openpgp
CVE-2019-12043 Vulnerability in maven package org.webjars.bower:remarkable
CVE-2021-23392 Vulnerability in npm package locutus
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-common
CVE-2020-7746 Vulnerability in maven package org.webjars.npm:chart.js