CRITICAL9.8
GHSA-29xr-v42j-r956
thenify before 3.3.1 made use of unsafe calls to `eval`.
Quick fix
GHSA-29xr-v42j-r956 — thenify: upgrade to the fixed version with the command below.
npm install thenify@3.3.1Details
Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars.npm:thenify
Introduced in:
0Fixed in: 3.3.1Fix
# pom.xml: bump <version>3.3.1</version> for org.webjars.npm:thenifyReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-7677[ADVISORY]
- https://github.com/thenables/thenify/issues/29[WEB]
- https://github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17a[WEB]
- https://github.com/thenables/thenify[PACKAGE]
- https://github.com/thenables/thenify/blob/master/index.js%23L17[WEB]
- https://lists.debian.org/debian-lts-announce/2022/09/msg00039.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317[WEB]
- https://security.snyk.io/vuln/SNYK-JS-THENIFY-571690[WEB]