Description
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
Remediation
References
https://snyk.io/vuln/SNYK-JS-HEROKUADDONPOOL-564428
https://github.com/nodef/heroku-addonpool/blob/master/index.js
Related Vulnerabilities
CVE-2023-41835 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-7680 Vulnerability in maven package org.webjars.npm:docsify
CVE-2020-15231 Vulnerability in maven package org.mapfish.print:print-lib
CVE-2020-15126 Vulnerability in npm package parse-server
CVE-2022-36881 Vulnerability in maven package org.jenkins-ci.plugins:git-client