Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Improper Input Validation in access-policy and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Input Validation in klona - CVE-2020-8125
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Improper Input Validation in Deap - CVE-2018-3749
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


