Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
https://openbase.io/js/apiconnect-cli-plugins
Related Vulnerabilities
CVE-2019-10742 Vulnerability in maven package org.webjars.bower:axios
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2022-0748 Vulnerability in npm package post-loader
CVE-2022-31151 Vulnerability in npm package undici
CVE-2022-36921 Vulnerability in maven package org.jenkins-ci.plugins:coverity