Description
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
Remediation
References
https://github.com/skoranga/node-connection-tester/pull/10
https://snyk.io/vuln/SNYK-JS-CONNECTIONTESTER-1048337
Related Vulnerabilities
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-core
CVE-2023-25571 Vulnerability in npm package @backstage/catalog-model
CVE-2023-48240 Vulnerability in maven package org.xwiki.platform:xwiki-platform-diff-xml
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes