Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2022-1233 Vulnerability in maven package org.webjars.npm:urijs
CVE-2020-8570 Vulnerability in maven package io.kubernetes:client-java
CVE-2023-41034 Vulnerability in maven package org.eclipse.leshan:leshan-core
CVE-2022-3510 Vulnerability in maven package com.google.protobuf:protobuf-javalite
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core