Описание
Replicator deserializes untrusted user input
An unauthenticated Remote Code Execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.
Пакеты
Наименование
replicator
npm
Затронутые версииВерсия исправления
<= 1.0.5
Отсутствует
Связанные уязвимости
CVSS3: 6.5
nvd
11 дней назад
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.