Description
All versions of package launchpad are vulnerable to Command Injection via stop.
Remediation
References
https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118
https://github.com/bitovi/launchpad/pull/124
https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065
Related Vulnerabilities
CVE-2016-10553 Vulnerability in npm package sequelize
CVE-2022-23106 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2022-22947 Vulnerability in maven package org.springframework.cloud:spring-cloud-gateway
CVE-2018-1000134 Vulnerability in maven package com.unboundid:unboundid-ldapsdk
CVE-2016-10586 Vulnerability in npm package macaca-chromedriver