Description
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
Remediation
References
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C
https://snyk.io/vuln/SNYK-JS-NODERULES-560426
Related Vulnerabilities
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui
CVE-2021-23417 Vulnerability in npm package deepmergefn
CVE-2023-3431 Vulnerability in maven package net.sourceforge.plantuml:plantuml
CVE-2020-14326 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2023-25569 Vulnerability in maven package com.ctrip.framework.apollo:apollo