OSV 1.4.0 · github-reviewed · 修改于 2021-07-28 06:20
发布时间
2019-10-22 05:58
GitHub 审查时间
2019-10-18 01:06
NVD 发布时间
2019-10-15 23:15
源文件
advisories/github-reviewed/2019/10/GHSA-r3x4-wr4h-pw33/GHSA-r3x4-wr4h-pw33.json
Versions of safer-eval prior to 1.3.4 are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. For example, evaluating he string console.constructor.constructor('return process')().env prints process.env to the console.
Upgrade to version 1.3.4 or later.