Description
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
Remediation
References
https://snyk.io/vuln/SNYK-JS-POMELOMONITOR-173695
https://github.com/halfblood369/monitor/blob/900b5cadf59edcccac4754e5706a22719925ddb9/lib/processMonitor.js%2C
Related Vulnerabilities
CVE-2021-4279 Vulnerability in maven package org.webjars.bower:fast-json-patch
CVE-2022-26049 Vulnerability in maven package com.diffplug.gradle:goomph
CVE-2022-37199 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2020-2118 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-githubnotify-step
CVE-2021-46036 Vulnerability in maven package net.mingsoft:ms-mcms