Lucene search

K
cveMitreCVE-2014-7205
HistoryOct 08, 2014 - 5:55 p.m.

CVE-2014-7205

2014-10-0817:55:05
CWE-94
mitre
web.nvd.nist.gov
32
cve
2014
7205
eval
injection
vulnerability
lib
batch.js
bassmaster
plugin
hapi
server
framework
node.js
javascript
code

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.895

Percentile

98.8%

Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.

Affected configurations

Nvd
Node
bassmaster_projectbassmasterRange<1.5.2
VendorProductVersionCPE
bassmaster_projectbassmaster*cpe:2.3:a:bassmaster_project:bassmaster:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.895

Percentile

98.8%