Логотип exploitDog
bind:CVE-2017-5941
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-5941

Количество 2

Количество 2

nvd логотип

CVE-2017-5941

почти 9 лет назад

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-q4v7-4rhw-9hqm

больше 7 лет назад

Code Execution through IIFE in node-serialize

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-5941

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

CVSS3: 9.8
78%
Высокий
почти 9 лет назад
github логотип
GHSA-q4v7-4rhw-9hqm

Code Execution through IIFE in node-serialize

CVSS3: 9.8
78%
Высокий
больше 7 лет назад

Уязвимостей на страницу