QID 983936
QID 983936: Nodejs (npm) Security Update for pouchdb (GHSA-cgqv-x5cx-xvqh)
Affected versions of `pouchdb` do not properly sandbox the code execution engine which executes the map/reduce functions for temporary views and design documents. Under certain circumstances, an attacker could uses this to run arbitrary code on the server. ## Recommendation Update to version 6.0.5 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cgqv-x5cx-xvqh for updates pertaining to this vulnerability.
Vendor References
- GHSA-cgqv-x5cx-xvqh -
github.com/advisories/GHSA-cgqv-x5cx-xvqh
CVEs related to QID 983936
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cgqv-x5cx-xvqh | pouchdb |
|