Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://openbase.io/js/apiconnect-cli-plugins
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
Related Vulnerabilities
CVE-2014-3579 Vulnerability in maven package org.apache.activemq:apollo-selector
CVE-2019-5438 Vulnerability in npm package harp
CVE-2020-28273 Vulnerability in npm package set-in
CVE-2016-4467 Vulnerability in maven package org.apache.qpid:proton-project
CVE-2017-12633 Vulnerability in maven package org.apache.camel:camel-hessian