This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2022-07-25T14:07:56.881504Z
Updated: 2024-09-17T01:36:04.103Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7678
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-25T14:15:10.100
Modified: 2024-11-21T05:37:35.750
Link: CVE-2020-7678
Redhat
No data.