PT-2020-21181 · Npm · Node-Rules

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions node-rules versions prior to 5.0.0
Description The issue arises from the package's failure to sanitize input rules, which are then passed directly to an eval call when using the fromJSON function. This may allow attackers to execute arbitrary code in the system if the rules are user-controlled.
Recommendations Upgrade to version 5.0.0 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-8WHR-V3GM-W8H9

Affected Products

Node-Rules