Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4660

Опубликовано: 28 июн. 2013
Источник: debian
EPSS Средний

Описание

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-js-yamlnot-affectedpackage

EPSS

Процентиль: 97%
0.17186
Средний

Связанные уязвимости

nvd
около 13 лет назад

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.

github
почти 9 лет назад

Deserialization Code Execution in js-yaml

EPSS

Процентиль: 97%
0.17186
Средний