Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29xr-v42j-r956

Опубликовано: 18 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

thenify before 3.3.1 made use of unsafe calls to eval.

Versions of thenify prior to 3.3.1 made use of unsafe calls to eval. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to eval.

Пакеты

Наименование

thenify

npm
Затронутые версииВерсия исправления

< 3.3.1

3.3.1

Наименование

org.webjars.npm:thenify

maven
Затронутые версииВерсия исправления

< 3.3.1

3.3.1

EPSS

Процентиль: 47%
0.00239
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 9.8
redhat
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 8.6
nvd
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 8.6
debian
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provi ...

EPSS

Процентиль: 47%
0.00239
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78