Skip to content

[VULN] Security Alert for node-serialize #991

@srm-local-dev-test

Description

@srm-local-dev-test

Alert IDs:

  • 09d839fc-d80b-4cfe-a4a4-8ae14cc2f2fe

Vulnerabilities in node-serialize

Release: 21st May Release

Total Vulnerabilities: 1


1. CVE-2017-5941

Severity: CRITICAL (Score: 7.0)

Description:
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-5941

Alert ID: 09d839fc-d80b-4cfe-a4a4-8ae14cc2f2fe


Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions