Description
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
Remediation
References
https://github.com/skoranga/node-connection-tester/pull/10
https://snyk.io/vuln/SNYK-JS-CONNECTIONTESTER-1048337
Related Vulnerabilities
CVE-2022-35948 Vulnerability in maven package org.webjars.npm:undici
CVE-2015-9236 Vulnerability in npm package hapi
CVE-2023-47325 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2018-1327 Vulnerability in maven package org.apache.struts:struts2-rest-plugin
CVE-2020-26258 Vulnerability in maven package com.thoughtworks.xstream:xstream