VDB
Sign up
CRITICAL9.8

GHSA-29xr-v42j-r956

thenify before 3.3.1 made use of unsafe calls to `eval`.

Quick fix

GHSA-29xr-v42j-r956 — thenify: upgrade to the fixed version with the command below.

npm install thenify@3.3.1

Details

Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/thenify
Introduced in: 0Fixed in: 3.3.1
Fixnpm install thenify@3.3.1
Maven/org.webjars.npm:thenify
Introduced in: 0Fixed in: 3.3.1
Fix# pom.xml: bump <version>3.3.1</version> for org.webjars.npm:thenify

References