OSV 1.4.0 · github-reviewed · 修改于 2021-07-30 02:12
发布时间
2021-05-18 05:00
GitHub 审查时间
2021-05-14 01:00
NVD 发布时间
2020-06-11 00:15
源文件
advisories/github-reviewed/2021/05/GHSA-cg42-4wrc-gp47/GHSA-cg42-4wrc-gp47.json
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument A of extend function(A,B,as,isAargs) located within lib/extend.js is executed by the eval function, resulting in code execution.