Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bc-fips-debug
CVE-2016-10562 Vulnerability in npm package iedriver
CVE-2023-37958 Vulnerability in maven package org.jenkins-ci.plugins:sumologic-publisher
CVE-2016-10546 Vulnerability in npm package pouchdb
CVE-2019-10459 Vulnerability in maven package org.jenkins-ci.plugins:mattermost