CVE-2020-7677: Arbitrary Code Execution
Published Jul 25, 2022
·Updated
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
Affected Software
4 affected components
Thenify Project Thenify Node.js<3.3.1
Debian Debian Linux=10.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Event History
Jul 25, 2022
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7677?
CVE-2020-7677 is classified as a high-severity vulnerability due to potential arbitrary code execution.
2
How do I fix CVE-2020-7677?
To fix CVE-2020-7677, upgrade to thenify version 3.3.1 or later.
3
Which software is affected by CVE-2020-7677?
CVE-2020-7677 affects versions of thenify before 3.3.1 across various platforms like Debian and Fedora.
4
What kind of vulnerability is CVE-2020-7677?
CVE-2020-7677 is a code injection vulnerability due to the lack of input sanitization.
5
Can CVE-2020-7677 lead to data breaches?
Yes, CVE-2020-7677 can lead to data breaches by allowing attackers to execute arbitrary code.