CVE-2020-7660: Code Injection
A flaw was found in the serialize-javascript before version 3.1.0. This flaw allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js."
Other sources
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-7660?
CVE-2020-7660 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-7660?
To fix CVE-2020-7660, upgrade the serialize-javascript package to version 3.1.0 or later.
Which software versions are affected by CVE-2020-7660?
CVE-2020-7660 affects versions of serialize-javascript prior to 3.1.0 and specific versions of servicemesh-grafana.
What type of vulnerability is CVE-2020-7660?
CVE-2020-7660 is a remote code execution vulnerability due to improper handling of user input.
Who is responsible for the CVE-2020-7660 vulnerability?
The CVE-2020-7660 vulnerability is attributed to the implementation in the serialize-javascript library.