joshnewton31080 / dvna

MIT License
0 stars 0 forks source link

CVE-2017-5941 (High) detected in node-serialize-0.0.4.tgz #8

Open mend-for-github-com[bot] opened 3 years ago

mend-for-github-com[bot] commented 3 years ago

CVE-2017-5941 - High Severity Vulnerability

Vulnerable Library - node-serialize-0.0.4.tgz

Serialize a object including it's function into a JSON.

Library home page: https://registry.npmjs.org/node-serialize/-/node-serialize-0.0.4.tgz

Path to dependency file: dvna/package.json

Path to vulnerable library: dvna/node_modules/node-serialize/package.json

Dependency Hierarchy: - :x: **node-serialize-0.0.4.tgz** (Vulnerable Library)

Found in HEAD commit: ebbe518de6103063656cb8a1c3d1040aacb09826

Found in base branch: main

Vulnerability Details

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

Publish Date: 2017-02-09

URL: CVE-2017-5941

CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.