PT-2016-3266 · Apache · Pouchdb

Publicado

2016-10-17

·

Atualizado

2019-10-09

·

CVE-2016-10546

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PouchDB versions prior to 6.0.5
Description A code injection vector was found in the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed, allowing an attacker to run arbitrary JavaScript as well as system commands. This issue is related to insufficient control of code generation. Under certain circumstances, an attacker could use this to run arbitrary code on the server.
Recommendations Update to version 6.0.5 or later. As a temporary workaround, consider disabling the map/reduce functions for temporary views and design documents until a patch is available.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00915
CVE-2016-10546
GHSA-CGQV-X5CX-XVQH

Produtos afetados

Pouchdb