Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2016-8745 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2020-2245 Vulnerability in maven package org.jenkins-ci.plugins:valgrind
CVE-2018-20677 Vulnerability in maven package org.webjars.bower:bootstrap
CVE-2017-2598 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-19919 Vulnerability in maven package org.webjars.npm:handlebars