CRITICAL
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript
Published Jan 23, 2017
9.8
CRITICALCVSS 3.1
EPSS 3.56%
Description
Affected products
Remediation
References (10)
Change history (0)
No recorded changes yet.