node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
References
Link | Resource |
---|---|
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832 | Patch Third Party Advisory |
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C | |
https://snyk.io/vuln/SNYK-JS-NODERULES-560426 | Exploit Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-04-27 22:15
Updated : 2023-11-07 03:26
NVD link : CVE-2020-7609
Mitre link : CVE-2020-7609
CVE.ORG link : CVE-2020-7609
JSON object : View
Products Affected
node-rules_project
- node-rules
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')