Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Remediation
References
https://github.com/mahdaen/node-import/blob/master/index.js%23L79
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691
Related Vulnerabilities
CVE-2021-34079 Vulnerability in npm package docker-tester
CVE-2018-10237 Vulnerability in maven package com.google.guava:guava
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net
CVE-2019-10779 Vulnerability in maven package stroom:stroom-app
CVE-2017-1000404 Vulnerability in maven package se.diabol.jenkins.pipeline:delivery-pipeline-plugin