Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ACCESSPOLICY-571490
Related Vulnerabilities
CVE-2021-43466 Vulnerability in maven package org.thymeleaf:thymeleaf-spring5
CVE-2019-10793 Vulnerability in npm package dot-object
CVE-2022-29258 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui
CVE-2023-30525 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2017-16036 Vulnerability in npm package badjs-sourcemap-server