Description
This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:
Remediation
References
https://snyk.io/vuln/SNYK-JS-TSPROCESSPROMISES-1048334
Related Vulnerabilities
CVE-2019-12728 Vulnerability in maven package org.grails:grails-core
CVE-2023-37947 Vulnerability in maven package org.openshift.jenkins:openshift-login
CVE-2023-29213 Vulnerability in maven package org.xwiki.platform:xwiki-platform-logging-script
CVE-2021-41189 Vulnerability in maven package org.dspace:dspace-api
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-nifi-parent