QID 981880
QID 981880: Nodejs (npm) Security Update for access-policy (GHSA-fw2f-7f87-5r6c)
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fw2f-7f87-5r6c for updates pertaining to this vulnerability.
Vendor References
- GHSA-fw2f-7f87-5r6c -
github.com/advisories/GHSA-fw2f-7f87-5r6c
CVEs related to QID 981880
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fw2f-7f87-5r6c | access-policy |
|