GHSA-f78f-353m-cf4j
CRITICALCVE-2020-7609node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
- Affected
- >= 3.0.0, < 5.0.0
- Fixed in
- 5.0.0
- Weakness
- CWE-94
- Published
- 2021-12-10
- Source
- github