Description
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5939 | The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor. |
Github GHSA |
GHSA-5gc4-cx9x-9c43 | Code Injection in metacalc |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T19:56:29.255Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-21122
No data.
Status : Modified
Published: 2022-06-08T09:15:08.470
Modified: 2024-11-21T06:43:56.573
Link: CVE-2022-21122
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA