QID 983490
QID 983490: Nodejs (npm) Security Update for uglify-js (GHSA-g6f4-j6c2-w3p3)
Withdrawn, accidental duplicate publish.
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g6f4-j6c2-w3p3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-g6f4-j6c2-w3p3 -
github.com/advisories/GHSA-g6f4-j6c2-w3p3
CVEs related to QID 983490
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g6f4-j6c2-w3p3 | uglify-js |
|