QID 982323
QID 982323: Nodejs (npm) Security Update for mathjs (GHSA-vx5c-87qx-cv6c)
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
## Recommendation
Update to version 3.17.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vx5c-87qx-cv6c for updates pertaining to this vulnerability.
Vendor References
- GHSA-vx5c-87qx-cv6c -
github.com/advisories/GHSA-vx5c-87qx-cv6c
CVEs related to QID 982323
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vx5c-87qx-cv6c | mathjs |
|