node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
References
Link | Resource |
---|---|
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C | |
https://snyk.io/vuln/SNYK-JS-NODERULES-560426 | Exploit Patch Third Party Advisory |
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832 | Patch Third Party Advisory |
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C | |
https://snyk.io/vuln/SNYK-JS-NODERULES-560426 | Exploit Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 05:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C - | |
References | () https://snyk.io/vuln/SNYK-JS-NODERULES-560426 - Exploit, Patch, Third Party Advisory |
07 Nov 2023, 03:26
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-04-27 22:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7609
Mitre link : CVE-2020-7609
CVE.ORG link : CVE-2020-7609
JSON object : View
Products Affected
node-rules_project
- node-rules
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')