Description
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4785
https://github.com/lifion/lifion-verify-deps/commit/be1133d5b78e3caa0004fa60207013dca4e1bf38
Related Vulnerabilities
CVE-2022-30506 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-38750 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-4040 Vulnerability in maven package org.apache.activemq:artemis-core-client
CVE-2010-1587 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r5