Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.1.0
References
Related Issues
- Improper Input Validation in klona - CVE-2020-8125
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Improper Input Validation in Deap - CVE-2018-3749
You might also like:
- Tags:
- npm
- access-policy
Anything's wrong? Let us know Last updated on February 01, 2023


