The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://hackerone.com/reports/390929 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2020-03-15T17:04:40
Updated: 2024-08-04T09:48:25.637Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8141
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-03-15T18:15:11.287
Modified: 2020-03-17T20:07:59.713
Link: CVE-2020-8141
Redhat
No data.