Логотип exploitDog
bind:CVE-2021-21278
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21278

Количество 2

Количество 2

nvd логотип

CVE-2021-21278

около 5 лет назад

RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a `no-new-func` rule to eslint.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-pgjj-866w-fc5c

больше 4 лет назад

Risk of code injection

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21278

RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a `no-new-func` rule to eslint.

CVSS3: 8.6
0%
Низкий
около 5 лет назад
github логотип
GHSA-pgjj-866w-fc5c

Risk of code injection

CVSS3: 8.6
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу