CRITICAL
Arbitrary Code Execution
Published Jul 25, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.13%
Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Affected products
- Vendor n/a Product Node-Import Defaultunknown
Affected
- ≥ 0, < unspecified
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Node-Import | unknown | Affected
|
- n/a
No data.
No Red Hat product state for this CVE.
node-import
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node-import | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6382 Advisory
- https://github.com/advisories/GHSA-pc62-cq5x-3j5g Advisory
- https://github.com/mahdaen/node-import/blob/master/index.js%23L79 x_refsource_MISCBroken LinkThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7678
- https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6382 | Advisory | |
| https://github.com/advisories/GHSA-pc62-cq5x-3j5g | Advisory | |
| https://github.com/mahdaen/node-import/blob/master/index.js%23L79 | x_refsource_MISCBroken LinkThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7678 | ||
| https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jul 25, 2022
Updated Sep 17, 2024
Reserved Jan 21, 2020
Link CVE-2020-7678
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-PC62-CQ5X-3J5G