PT-2019-12041 · Npm · Safe-Eval
Jonathan Leitschuh
·
Publicado
2019-12-06
·
Atualizado
2021-07-21
·
CVE-2019-10769
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
safer-eval versions all
Description
The issue concerns the safer-eval npm package, which is used to sandbox the evaluation of code within the eval function. It is vulnerable to Arbitrary Code Execution via generating a RangeError and Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context and is not suited to process arbitrary user input, potentially allowing attackers to execute arbitrary code in the system.
Recommendations
For all versions, consider using an alternative package until a fix is made available, as the safer-eval package is not meant to receive user input.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Safe-Eval