Описание
npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Ссылки
- Product
- Product
- Product
- PatchIssue Tracking
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 25%
0.00088
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321
Связанные уязвимости
EPSS
Процентиль: 25%
0.00088
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321