CRITICAL 9.8 npm
Improper Input Validation in access-policy
GHSA-fw2f-7f87-5r6c · CVE-2020-7674 · SNYK-JS-ACCESSPOLICY-571490
Published · Modified
Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code execution.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes