CVE-2021-42139

Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
References
Link Resource
https://github.com/denoland/deno_std/pull/1275 Exploit Third Party Advisory
https://github.com/denoland/deno_std/releases/tag/0.107.0 Release Notes Third Party Advisory
https://vuln.ryotak.me/advisories/58 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:deno:deno_standard_modules:*:*:*:*:*:*:*:*

History

04 Nov 2021, 12:47

Type Values Removed Values Added
CPE cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:* cpe:2.3:a:deno:deno_standard_modules:*:*:*:*:*:*:*:*
References (MISC) https://github.com/denoland/deno_std/releases/tag/0.107.0 - Third Party Advisory (MISC) https://github.com/denoland/deno_std/releases/tag/0.107.0 - Release Notes, Third Party Advisory

25 Oct 2021, 02:15

Type Values Removed Values Added
Summary Deno before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.

19 Oct 2021, 17:28

Type Values Removed Values Added
CPE cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*
References (MISC) https://github.com/denoland/deno_std/pull/1275 - (MISC) https://github.com/denoland/deno_std/pull/1275 - Exploit, Third Party Advisory
References (MISC) https://vuln.ryotak.me/advisories/58 - (MISC) https://vuln.ryotak.me/advisories/58 - Third Party Advisory
References (MISC) https://github.com/denoland/deno_std/releases/tag/0.107.0 - (MISC) https://github.com/denoland/deno_std/releases/tag/0.107.0 - Third Party Advisory
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 9.8

11 Oct 2021, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-11 05:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-42139

Mitre link : CVE-2021-42139

CVE.ORG link : CVE-2021-42139


JSON object : View

Products Affected

deno

  • deno_standard_modules
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')