QID 983925
QID 983925: Nodejs (npm) Security Update for apex-publish-static-files (GHSA-9jm3-5835-537m)
Versions of `apex-publish-static-files` before 2.0.1 are vulnerable to command injection. This is exploitable if user input is passed into the `connectString` option in the `publish` method. ## Recommendation Update to version 2.0.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9jm3-5835-537m for updates pertaining to this vulnerability.
Vendor References
- GHSA-9jm3-5835-537m -
github.com/advisories/GHSA-9jm3-5835-537m
CVEs related to QID 983925
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9jm3-5835-537m | apex-publish-static-files |
|