Description
This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.
Remediation
References
https://github.com/cliftonc/calipso
https://snyk.io/vuln/SNYK-JS-CALIPSO-1300555
Related Vulnerabilities
CVE-2016-5005 Vulnerability in maven package org.apache.archiva:archiva
CVE-2019-10768 Vulnerability in maven package org.webjars.bower:angular
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:arquillian-tomee-embedded
CVE-2021-43821 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl
CVE-2014-3651 Vulnerability in maven package org.keycloak:keycloak-services