CRITICAL9.8
GHSA-3gx7-xhv7-5mx3
Arbitrary Code Execution in eslint-utils
Quick fix
GHSA-3gx7-xhv7-5mx3 — eslint-utils: upgrade to the fixed version with the command below.
npm install eslint-utils@1.4.1Details
Versions of `eslint-utils` >=1.2.0 or <1.4.1 are vulnerable to Arbitrary Code Execution. The `getStaticValue` does not properly sanitize user input allowing attackers to supply malicious input that executes arbitrary code during the linting process. The `getStringIfConstant` and `getPropertyName` functions are not affected.
## Recommendation
Upgrade to version 1.4.1 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mysticatea/eslint-utils/security/advisories/GHSA-3gx7-xhv7-5mx3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2019-15657[ADVISORY]
- https://github.com/mysticatea/eslint-utils/commit/08158db1c98fd71cf0f32ddefbc147e2620e724c[WEB]
- https://eslint.org/blog/2019/08/eslint-v6.2.1-released[WEB]
- https://github.com/advisories/GHSA-3gx7-xhv7-5mx3[ADVISORY]
- https://github.com/mysticatea/eslint-utils[PACKAGE]
- https://www.npmjs.com/advisories/1118[WEB]