Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.
References
Configurations
No configuration.
History
01 Nov 2024, 12:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
31 Oct 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-31 05:15
Updated : 2024-11-01 12:57
NVD link : CVE-2024-21537
Mitre link : CVE-2024-21537
CVE.ORG link : CVE-2024-21537
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')