Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://openbase.io/js/apiconnect-cli-plugins
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
Related Vulnerabilities
CVE-2021-32854 Vulnerability in maven package org.webjars.npm:textangular
CVE-2019-10370 Vulnerability in maven package org.jenkins-ci.plugins:mask-passwords
CVE-2021-23337 Vulnerability in npm package lodash
CVE-2020-26302 Vulnerability in maven package org.webjars.bower:is_js
CVE-2022-39387 Vulnerability in maven package org.xwiki.contrib.oidc:oidc-authenticator