Description
All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-WIFEY-3175615
Related Vulnerabilities
CVE-2020-17510 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-web-starter
CVE-2021-43776 Vulnerability in npm package @backstage/plugin-auth-backend
CVE-2020-17527 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-23820 Vulnerability in npm package json-pointer
CVE-2023-43642 Vulnerability in maven package org.xerial.snappy:snappy-java