Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q849-wxrc-vqrp

Опубликовано: 02 дек. 2024
Источник: github
Github: Прошло ревью

Описание

hull.js Code Injection Vulnerability

Versions of the library from 0.2.2 to 1.0.9 are vulnerable to the arbitrary code execution due to unsafe usage of new Function(...) in the module that handles points format. Applications passing the 3rd parameter to the hull function without sanitising may be impacted. The vulnerability has been fixed in version 1.0.10, please update the library. Check project homepage on GitHub to see how to fetch the latest version: https://github.com/andriiheonia/hull?tab=readme-ov-file#npm-package

Пакеты

Наименование

hull.js

npm
Затронутые версииВерсия исправления

>= 0.2.2, < 1.0.10

1.0.10

Дефекты

CWE-94

Дефекты

CWE-94