Lucene search

K
osvGoogleOSV:GHSA-CWCP-6C48-FM7M
HistorySep 01, 2020 - 4:39 p.m.

Unsafe eval() in summit allows arbitrary code execution

2020-09-0116:39:38
Google
osv.dev
6
unsafe eval
summit
arbitrary code execution
affected versions
pouchdb driver
mitigation
package author

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

58.8%

Affected versions of summit allow attackers to execute arbitrary commands via collection names when using the PouchDB driver.

Recommendation

No direct patch is available at this time.

Currently, the best option to mitigate the issue is to avoid using the PouchDB driver, as the package author has abandoned this feature entirely.

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

58.8%

Related for OSV:GHSA-CWCP-6C48-FM7M