Description
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Remediation
References
https://github.com/totaljs/framework/commit/c812bbcab8981797d3a1b9993fc42dad3d246f04
https://snyk.io/vuln/SNYK-JS-TOTALJS-1077069
Related Vulnerabilities
CVE-2022-24823 Vulnerability in maven package io.netty:netty-common
CVE-2022-31083 Vulnerability in npm package parse-server
CVE-2020-28446 Vulnerability in npm package ntesseract
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2019-1003049 Vulnerability in maven package org.jenkins-ci.main:jenkins-core