Description
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Remediation
References
https://github.com/totaljs/framework/commit/c812bbcab8981797d3a1b9993fc42dad3d246f04
https://snyk.io/vuln/SNYK-JS-TOTALJS-1077069
Related Vulnerabilities
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2021-3645 Vulnerability in npm package @viking04/merge
CVE-2021-23784 Vulnerability in npm package tempura
CVE-2020-7676 Vulnerability in maven package org.webjars.npm:angular
CVE-2022-28366 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml