Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ACCESSPOLICY-571490
Related Vulnerabilities
CVE-2022-42466 Vulnerability in maven package org.apache.isis.commons:isis-commons
CVE-2020-7723 Vulnerability in npm package promisehelpers
CVE-2021-34429 Vulnerability in maven package org.eclipse.jetty:jetty-webapp
CVE-2018-3720 Vulnerability in npm package assign-deep
CVE-2022-31053 Vulnerability in maven package com.clever-cloud:biscuit-java