Lucene search

K
nodejsCristian-Alexandru StaicuNODEJS:315
HistoryMar 06, 2017 - 9:27 p.m.

Unsafe eval()

2017-03-0621:27:13
Cristian-Alexandru Staicu
www.npmjs.com
35

0.002 Low

EPSS

Percentile

58.8%

Overview

Affected versions of summit allow attackers to execute arbitrary commands via collection names when using the PouchDB driver.

Recommendation

No direct patch is available at this time.

Currently, the best option to mitigate the issue is to avoid using the PouchDB driver, as the package author has abandoned this feature entirely.

References

CPENameOperatorVersion
summitge0.1.0

0.002 Low

EPSS

Percentile

58.8%