Description
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ACCESSPOLICY-571490
Related Vulnerabilities
CVE-2022-41965 Vulnerability in maven package org.opencastproject:opencast-engage-paella-player
CVE-2022-21676 Vulnerability in npm package engine.io
CVE-2020-8158 Vulnerability in npm package typeorm
CVE-2021-23472 Vulnerability in npm package bootstrap-table
CVE-2020-7660 Vulnerability in npm package serialize-javascript