CVE-2020-8141
Summary
| CVE | CVE-2020-8141 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-15 18:15:00 UTC |
| Updated | 2020-03-17 20:07:00 UTC |
| Description | The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| HackerOne |
MISC |
hackerone.com |
Exploit, Mitigation, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375626 IBM Cognos Analytics Multiple Vulnerabilities (6451705)
- 375661 Node.js Dot v1.1.2 Code Injection Vulnerability