QID 983490

QID 983490: Nodejs (npm) Security Update for uglify-js (GHSA-g6f4-j6c2-w3p3)

Withdrawn, accidental duplicate publish.

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-g6f4-j6c2-w3p3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983490

    Software Advisories
    Advisory ID Software Component Link
    GHSA-g6f4-j6c2-w3p3 uglify-js URL Logo github.com/advisories/GHSA-g6f4-j6c2-w3p3