Description
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
Remediation
References
https://github.com/strongloop/strong-nginx-controller/blob/master/lib/server.js#L65%2C
https://snyk.io/vuln/SNYK-JS-STRONGNGINXCONTROLLER-564248
Related Vulnerabilities
CVE-2020-7755 Vulnerability in npm package dat.gui
CVE-2016-1000346 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2020-10650 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-25053 Vulnerability in npm package node-json2html
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs