← Volver a CVEs
CVE-2020-6836
CRITICAL9.8
Descripcion
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/11/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
hot-formula-parser_project:hot-formula-parser
Debilidades (CWE)
CWE-94
Referencias
https://github.com/handsontable/formula-parser/commit/396b089738d4bf30eb570a4fe6a188affa95cd5e(cve@mitre.org)
https://www.npmjs.com/advisories/1439(cve@mitre.org)
https://blog.truesec.com/2020/01/17/reverse-shell-through-a-node-js-math-parser/(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/handsontable/formula-parser/commit/396b089738d4bf30eb570a4fe6a188affa95cd5e(af854a3a-2127-422b-91ae-364da2661108)
https://www.npmjs.com/advisories/1439(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.