Description
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
Remediation
References
https://openbase.io/js/apiconnect-cli-plugins
https://snyk.io/vuln/SNYK-JS-APICONNECTCLIPLUGINS-564427
Related Vulnerabilities
CVE-2018-3743 Vulnerability in npm package hekto
CVE-2020-7727 Vulnerability in npm package gedi
CVE-2019-0188 Vulnerability in maven package org.apache.camel:camel-xmljson
CVE-2022-21724 Vulnerability in maven package org.postgresql:postgresql
CVE-2020-36181 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind