Description
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
Remediation
References
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832
https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C
https://snyk.io/vuln/SNYK-JS-NODERULES-560426
Related Vulnerabilities
CVE-2023-3635 Vulnerability in maven package com.squareup.okio:okio
CVE-2020-7611 Vulnerability in maven package io.micronaut:micronaut-http-client
CVE-2020-7677 Vulnerability in maven package org.webjars.npm:thenify
CVE-2018-3721 Vulnerability in npm package @sailshq/lodash
CVE-2020-2164 Vulnerability in maven package org.jenkins-ci.plugins:artifactory