Description
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Remediation
References
https://github.com/josdejong/typed-function/commit/6478ef4f2c3f3c2d9f2c820e2db4b4ba3425e6fe
https://github.com/josdejong/typed-function/blob/master/HISTORY.md#2017-11-18-version-0106
Related Vulnerabilities
CVE-2013-1821 Vulnerability in maven package org.jruby:jruby
CVE-2017-1000189 Vulnerability in maven package org.webjars.npm:ejs
CVE-2018-3719 Vulnerability in npm package mixin-deep
CVE-2018-1000023 Vulnerability in npm package insight-api
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http