apex-publish-static-files@1.0.6 vulnerabilities

Allows to publish an entire local directory to Oracle APEX Shared Components.

Direct Vulnerabilities

Known vulnerabilities in the apex-publish-static-files package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Arbitrary Command Injection

apex-publish-static-files Uploads all files from a local directory to Oracle APEX.

Affected versions of this package are vulnerable to Arbitrary Command Injection. It does not sanitize the connectionString argument, and subsequently passes it to execSync(), thus allowing arbitrary shell command injection.

How to fix Arbitrary Command Injection?

Upgrade apex-publish-static-files to version 2.0.1 or higher.

<2.0.1