Vulnerabilities/

Code Injection in node-rules

Severity:
High

Description

node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function “fromJSON()” can be controlled by users without any sanitization.

Recommendation

Update the node-rules package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-rules
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing