PT-2022-17496 · Accesslog · Accesslog

Omnitaint

·

Published

2022-03-17

·

Updated

2022-03-23

·

CVE-2022-25760

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions accesslog versions all
Description The issue arises from the usage of the Function constructor without input sanitization in the package's exported constructor function. If attacker-controlled user input is given to the format option, it is possible for an attacker to execute arbitrary JavaScript code on the host.
Recommendations For all versions, consider disabling the usage of the Function constructor with user-controlled input until a patch is available. Restrict access to the format option of the package's exported constructor function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25760
GHSA-8M2F-74R2-X3F2
SNYK-JS-ACCESSLOG-2312099

Affected Products

Accesslog