HIGH
The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function()" substring, as demonstrated by a "function(){console.log(" call or a simple infinite loop
Published Oct 24, 2017
7.5
HIGHCVSS 3.1
EPSS 1.15%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.