CVE-2020-7678
Summary
| CVE | CVE-2020-7678 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-25 14:15:00 UTC |
| Updated | 2022-08-01 17:38:00 UTC |
| Description | This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js". |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Node-import Project | Node-import | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Arbitrary Code Execution in node-import | CVE-2020-7678 | Snyk | CONFIRM | security.snyk.io | |
| N/A | CONFIRM | github.com | |
| node-import/index.js at master · mahdaen/node-import · GitHub | MITRE | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: JHU System Security Lab
There are currently no legacy QID mappings associated with this CVE.