Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5726-g6r9-5f22

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Potential for Script Injection in syntax-error

Versions of syntax-error prior to 1.1.1 are affected by a cross-site scripting vulnerability which may allow a malicious file to execute code when browserified.

Recommendation

Update to version 1.1.1 or later.

Пакеты

Наименование

syntax-error

npm
Затронутые версииВерсия исправления

< 1.1.1

1.1.1

EPSS

Процентиль: 97%
0.43935
Средний

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 10 лет назад

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

nvd
больше 10 лет назад

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

debian
больше 10 лет назад

Eval injection vulnerability in index.js in the syntax-error package b ...

EPSS

Процентиль: 97%
0.43935
Средний

Дефекты

CWE-94