Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-7677

Опубликовано: 25 июл. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 8.6

Описание

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

РелизСтатусПримечание
bionic

released

3.3.0-1+deb10u1build0.18.04.1
devel

not-affected

esm-apps/bionic

released

3.3.0-1+deb10u1build0.18.04.1
esm-apps/focal

released

3.3.0-1+deb10u1build0.20.04.1
esm-apps/jammy

not-affected

3.3.1-2
focal

released

3.3.0-1+deb10u1build0.20.04.1
jammy

not-affected

3.3.1-2
kinetic

not-affected

lunar

not-affected

trusty

DNE

Показывать по

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 8.6
nvd
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVSS3: 8.6
debian
больше 3 лет назад

This affects the package thenify before 3.3.1. The name argument provi ...

CVSS3: 9.8
github
больше 3 лет назад

thenify before 3.3.1 made use of unsafe calls to `eval`.

8.6 High

CVSS3