Description
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Remediation
References
https://github.com/totaljs/framework/commit/c812bbcab8981797d3a1b9993fc42dad3d246f04
https://snyk.io/vuln/SNYK-JS-TOTALJS-1077069
Related Vulnerabilities
CVE-2016-1181 Vulnerability in maven package struts:struts
CVE-2020-11998 Vulnerability in maven package org.apache.activemq:activemq-broker
CVE-2011-5063 Vulnerability in maven package tomcat:catalina
CVE-2022-31194 Vulnerability in maven package org.dspace:dspace-jspui
CVE-2007-5613 Vulnerability in maven package org.mortbay.jetty:jetty