← לוח פגיעויות

CVE-2020-7712

גבוהה 7.2

תיאור (מקור, אנגלית)

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

מדדים

CVSS 3.1
7.2 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78

מוצרים מושפעים

joyent: json; oracle: commerce guided search; oracle: financial services crime and compliance management studio; oracle: financial services regulatory reporting with agilereporter; oracle: timesten in-memory database

קישורים