PT-2019-12041 · Npm · Safe-Eval

Jonathan Leitschuh

·

Publicado

2019-12-06

·

Atualizado

2021-07-21

·

CVE-2019-10769

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions safer-eval versions all
Description The issue concerns the safer-eval npm package, which is used to sandbox the evaluation of code within the eval function. It is vulnerable to Arbitrary Code Execution via generating a RangeError and Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context and is not suited to process arbitrary user input, potentially allowing attackers to execute arbitrary code in the system.
Recommendations For all versions, consider using an alternative package until a fix is made available, as the safer-eval package is not meant to receive user input.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10769
GHSA-V63X-XC9J-HHVQ
SNYK-JS-SAFEREVAL-534901

Produtos afetados

Safe-Eval