Description
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
Remediation
References
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832
https://snyk.io/vuln/SNYK-JS-NODERULES-560426
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C
Related Vulnerabilities
CVE-2018-12023 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2010-2057 Vulnerability in maven package org.apache.myfaces.shared:myfaces-shared-impl
CVE-2023-1283 Vulnerability in npm package @builder.io/qwik
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2019-3799 Vulnerability in maven package org.springframework.cloud:spring-cloud-config-server