PT-2022-17605 · Unknown · Morgan-Json

Omnitaint

·

Published

2022-08-29

·

Updated

2023-08-08

·

CVE-2022-25921

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions morgan-json versions all
Description The issue is related to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor. This allows for potential code execution with unintended consequences. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For morgan-json versions all, consider disabling the use of the Function constructor until a patch is available. Restrict input passed to this constructor to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-25921
GHSA-FWV4-6MXC-X5H3

Affected Products

Morgan-Json