In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade cli-onprem to version 1.5.1 or higher.
cli-onprem is a CLI tool for infrastructure engineers
Affected versions of this package are vulnerable to Command Injection due to the use of shell-invoked subprocess calls with unvalidated input. An attacker can execute arbitrary commands by injecting shell metacharacters in the directory and pattern variables used by the calculate_sha256_manifest and merge_files functions.