Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ACCESSPOLICY-571490
Related Vulnerabilities
CVE-2023-26102 Vulnerability in npm package rangy
CVE-2020-7608 Vulnerability in npm package yargs-parser
CVE-2022-29647 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-29210 Vulnerability in maven package org.xwiki.platform:xwiki-platform-notifications-ui
CVE-2023-34238 Vulnerability in npm package gatsby-plugin-sharp