Описание
npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Ссылки
- Product
- Product
- Product
- Issue TrackingPatch
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 37%
0.00452
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321
Связанные уязвимости
CVSS3: 7.3
redhat
10 месяцев назад
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
EPSS
Процентиль: 37%
0.00452
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321