Description
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".
Remediation
References
https://snyk.io/vuln/SNYK-JS-AWSLAMBDA-540839
Related Vulnerabilities
CVE-2017-16095 Vulnerability in npm package serverliujiayi1
CVE-2018-18893 Vulnerability in maven package com.hubspot.jinjava:jinjava
CVE-2019-9843 Vulnerability in maven package com.diffplug.spotless:spotless-maven-plugin
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2017-18349 Vulnerability in maven package com.alibaba:fastjson