Description
All versions of package launchpad are vulnerable to Command Injection via stop.
Remediation
References
https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118
https://github.com/bitovi/launchpad/pull/124
https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065
Related Vulnerabilities
CVE-2021-37695 Vulnerability in npm package ckeditor4
CVE-2020-2243 Vulnerability in maven package org.jenkins-ci.plugins:vmanager-plugin
CVE-2014-3630 Vulnerability in maven package com.typesafe.akka:akka-http-xml-experimental_2.11
CVE-2018-1000665 Vulnerability in maven package org.webjars.bower:dojo
CVE-2016-2173 Vulnerability in maven package org.springframework.amqp:spring-amqp