9.8
CVE-2020-7677
- EPSS 0.2%
- Veröffentlicht 25.07.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:35
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Thenify Project ≫ Thenify SwPlatformnode.js Version < 3.3.1
Debian ≫ Debian Linux Version10.0
Fedoraproject ≫ Fedora Version36
Fedoraproject ≫ Fedora Version37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.423 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| report@snyk.io | 8.6 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
|