Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Remediation
References
https://github.com/mahdaen/node-import/blob/master/index.js%23L79
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691
Related Vulnerabilities
CVE-2019-10287 Vulnerability in maven package org.jenkins-ci.plugins:youtrack-plugin
CVE-2020-7777 Vulnerability in npm package jsen
CVE-2019-16776 Vulnerability in maven package org.webjars.bower:npm
CVE-2020-7679 Vulnerability in maven package org.webjars.bower:casperjs
CVE-2019-9154 Vulnerability in maven package org.webjars.npm:openpgp