Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8h4-vw8f-rvvj

Опубликовано: 13 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Control of Dynamically-Managed Code Resources in config-shield

scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data.

Пакеты

Наименование

config-shield

npm
Затронутые версииВерсия исправления

< 0.2.3

0.2.3

EPSS

Процентиль: 46%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-913

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data

EPSS

Процентиль: 46%
0.00237
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-913