Описание
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.
Ссылки
- Third Party Advisory
- Product
- Product
- Issue TrackingPatch
- Third Party Advisory
- Product
- Product
- Third Party Advisory
- Product
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.
expr-eval does not restrict functions passed to the evaluate function
Уязвимость функции estimate() библиотеки expr-eval, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3