Description
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
Remediation
References
https://github.com/nodef/heroku-addonpool/blob/master/index.js
https://snyk.io/vuln/SNYK-JS-HEROKUADDONPOOL-564428
Related Vulnerabilities
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2020-7784 Vulnerability in npm package ts-process-promises
CVE-2022-23221 Vulnerability in maven package com.h2database:h2
CVE-2021-25738 Vulnerability in maven package io.kubernetes:client-java-parent
CVE-2022-28150 Vulnerability in maven package com.synopsys.jenkinsci:ownership