Risk of code injection
Description
Published by the National Vulnerability Database
Jan 26, 2021
Reviewed
Oct 11, 2021
Published to the GitHub Advisory Database
Oct 12, 2021
Last updated
Feb 1, 2023
Impact
Some routes use
eval
orFunction constructor
, which may be injected by the target site with unsafe code, causing server-side security issuesPatches
Temporarily removed the problematic route and added a
no-new-func
rule to eslintSelf-built users should upgrade to 7f1c430 and later as soon as possible
Credits
Tencent Woodpecker Security Team
For more information
If you have any questions or comments about this advisory:
References