Description
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
Remediation
References
https://github.com/nodef/heroku-addonpool/blob/master/index.js
https://snyk.io/vuln/SNYK-JS-HEROKUADDONPOOL-564428
Related Vulnerabilities
CVE-2023-34613 Vulnerability in maven package net.sf.sojo:sojo
CVE-2016-5005 Vulnerability in maven package org.apache.archiva:archiva
CVE-2022-29078 Vulnerability in maven package org.webjars.npm:ejs
CVE-2018-3722 Vulnerability in npm package merge-deep
CVE-2021-23329 Vulnerability in npm package nested-object-assign