Описание
All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.4.1 (включая)
cpe:2.3:a:safe-eval_project:safe-eval:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 52%
0.00291
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-1321
CWE-1321
Связанные уязвимости
EPSS
Процентиль: 52%
0.00291
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-1321
CWE-1321