Description
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-HEROKUENV-1050432
Related Vulnerabilities
CVE-2021-35513 Vulnerability in npm package mermaid
CVE-2020-8203 Vulnerability in npm package lodash
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core
CVE-2021-23362 Vulnerability in maven package org.webjars.npm:hosted-git-info
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web