Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m2f-74r2-x3f2

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Code injection in accesslog

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.

Пакеты

Наименование

accesslog

npm
Затронутые версииВерсия исправления

<= 0.0.2

Отсутствует

EPSS

Процентиль: 64%
0.0046
Низкий

7.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.1
nvd
почти 4 года назад

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.

EPSS

Процентиль: 64%
0.0046
Низкий

7.1 High

CVSS3

Дефекты

CWE-94