CVE-2020-7609
27.04.2020, 22:15
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
Vendor | Product | Version |
---|---|---|
node-rules_project | node-rules | 3.0.0 ≤ 𝑥 < 5.0.0 |
𝑥
= Vulnerable software versions
References