Description
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
Remediation
References
https://github.com/skoranga/node-connection-tester/pull/10
https://snyk.io/vuln/SNYK-JS-CONNECTIONTESTER-1048337
Related Vulnerabilities
CVE-2022-1929 Vulnerability in npm package devcert
CVE-2021-32621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-dashboard-macro
CVE-2020-7639 Vulnerability in npm package eivindfjeldstad-dot
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2021-34078 Vulnerability in npm package lifion-verify-deps