Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://openbase.io/js/apiconnect-cli-plugins
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
Related Vulnerabilities
CVE-2019-11003 Vulnerability in npm package materialize-css
CVE-2021-41184 Vulnerability in maven package org.webjars:jquery-ui
CVE-2021-37695 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2020-15123 Vulnerability in npm package codecov
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom