Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://openbase.io/js/apiconnect-cli-plugins
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
Related Vulnerabilities
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-engineplugin-jdbc
CVE-2018-3750 Vulnerability in maven package org.webjars.npm:deep-extend
CVE-2020-7792 Vulnerability in npm package mout
CVE-2023-45818 Vulnerability in npm package tinymce
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-snowflake