Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Remediation
References
https://github.com/notduncansmith/summit/issues/23
https://nodesecurity.io/advisories/315
Related Vulnerabilities
CVE-2022-41918 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2019-20444 Vulnerability in maven package io.netty:netty-codec-http
CVE-2017-9804 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-10793 Vulnerability in npm package dot-object
CVE-2021-23346 Vulnerability in npm package html-parse-stringify2