This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
References
Link | Resource |
---|---|
https://github.com/mahdaen/node-import/blob/master/index.js%23L79 | Broken Link Third Party Advisory |
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 | Exploit Third Party Advisory |
https://github.com/mahdaen/node-import/blob/master/index.js%23L79 | Broken Link Third Party Advisory |
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:37
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
References | () https://github.com/mahdaen/node-import/blob/master/index.js%23L79 - Broken Link, Third Party Advisory | |
References | () https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 - Exploit, Third Party Advisory |
01 Aug 2022, 17:38
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (CONFIRM) https://github.com/mahdaen/node-import/blob/master/index.js%23L79 - Broken Link, Third Party Advisory | |
References | (CONFIRM) https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:node-import_project:node-import:*:*:*:*:*:node.js:*:* |
25 Jul 2022, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-25 14:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7678
Mitre link : CVE-2020-7678
CVE.ORG link : CVE-2020-7678
JSON object : View
Products Affected
node-import_project
- node-import
CWE