CVE-2017-16020

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
References
Link Resource
https://github.com/notduncansmith/summit/issues/23 Third Party Advisory
https://nodesecurity.io/advisories/315 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:summit_project:summit:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2018-06-04 19:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-16020

Mitre link : CVE-2017-16020

CVE.ORG link : CVE-2017-16020


JSON object : View

Products Affected

summit_project

  • summit
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')