Описание
morgan-json vulnerable to Arbitrary Code Execution
All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor.
Пакеты
Наименование
morgan-json
npm
Затронутые версииВерсия исправления
<= 1.1.0
Отсутствует
Связанные уязвимости
CVSS3: 8.1
nvd
больше 3 лет назад
All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor.