• About
  • Advertise
  • Privacy & Policy
  • Contact
Internet Starters
  • Home
  • Branding
  • Computers
  • Internet Starters
  • Marketing Tips
  • The Internet
No Result
View All Result
  • Home
  • Branding
  • Computers
  • Internet Starters
  • Marketing Tips
  • The Internet
No Result
View All Result
Internet Starters
No Result
View All Result
Home Branding

Safer-Eval library branded ‘harmful’ with no patch planned

Inter 2025 by Inter 2025
December 10, 2019
Safer-Eval library branded ‘harmful’ with no patch planned
Share on FacebookShare on Twitter

[ad_1]

An RCE vulnerability within the node.js module is not going to be mounted

Safer-Eval library branded ‘harmful’ with no patch planned

A vital vulnerability impacting safer-eval runs the danger of impacting over 36,000 tasks dependant on the node JS library, a software program engineer has warned.

The bug – CVE-2019-10769 – might result in various points, together with a sandbox bypass, cross-site scripting (XSS), or distant code execution (RCE), Jonathan Leitschuh, software program engineer at Gradle, disclosed yesterday (December 9) over Twitter.

Over 36,000 tasks use the weak library, Leitschuh famous. All variations are impacted and in accordance with a GitHub advisory revealed late final week, no patch has been issued.

Safer-Eval is a node.js library open sourced below the MIT license and designed as an alternative choice to the JS customary library’s eval perform.

It’s supposed to judge JavaScript in a sandbox, permitting some expressions, whereas throwing others away in an effort to forestall XSS and RCE.

As described by developer Robert Webb, the essential eval perform is taken into account by some as “just one letter away from evil.” By together with the eval perform in a code base, he says, “you can be encouraging future builders to make use of it for dangerous functions.”

YOU MIGHT ALSO LIKE The whole bundle: The whole lot you could find out about nmp safety

On December 6, the bundle writer revealed a warning to safer-eval customers – of which there have been over 50,000 downloads in the course of the previous week from the code repository – that the module needs to be thought of “dangerous”.

“Earlier than utilizing this module, ask your self if there aren’t any higher choices than utilizing safer-eval,” the advisory mentioned.

“It’s probably higher than the dangerous previous however has dangerous potential”.

The identical warning has been revealed on the safer-eval GitHub undertaking web page.

This doubtless pertains to the current launch of proof-of-concept (PoC) exploit code capable of abuse a vital safer-eval vulnerability.

In April, GitHub person XmiliaH additionally revealed PoC code capable of trigger a sandbox breakout in vm2 by way of the era of a spread error.

As soon as examined by XmiliaH, nonetheless, they branded using a spread error as “overkill,” resulting in a less complicated PoC being written and revealed by the developer.

Earlier variations of safer-eval – 1.three.three and beneath – have been moreover discovered to be weak to a sandbox bypass and RCE assault by malicious payloads capable of tamper with constructor strings.

This vulnerability is tracked as CVE-2019-10759 and was made public in July.

Within the absence of patch improvement for the brand new exploit, safer-eval has beneficial vm2 in its place and has inspired the general public posting of exploits in opposition to the module with a purpose to “assist others to construct a greater sandbox”.



[ad_2]

Source link

Inter 2025

Inter 2025

Next Post
This object-recognition dataset stumped the world’s best computer vision models

This object-recognition dataset stumped the world’s best computer vision models

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Kaiser Permanente computer system down for five hours during coronavirus pandemic

Kaiser Permanente computer system down for five hours during coronavirus pandemic

June 15, 2020
Big One

Waiting for the Big One. Then coronavirus arrived.

April 16, 2020

Trending.

The 6 best Linux desktop PCs in 2024

The 6 best Linux desktop PCs in 2024

April 7, 2024
cellular

Pros and Cons to using Wi-Fi and Cellular Internet

February 18, 2020
Thanks to the internet the 2010s were the decade of people power

Thanks to the internet the 2010s were the decade of people power

December 24, 2019
Social media

10 Books That Show Tech & Social Media Are a Total Story Starters

February 15, 2020
Joe Szynkowski: Quick tips to improve your LinkedIn profile | Local Business

Joe Szynkowski: Quick tips to improve your LinkedIn profile | Local Business

January 29, 2022

Follow Us

Categories

  • Branding
  • Computers
  • Internet Starters
  • Marketing Tips
  • The Internet
Internet Starters

RSS Live Software news

  • The Ultimate Guide to Bandwidth Monitoring.
  • Website Traffic Monitor
  • About
  • Advertise
  • Privacy & Policy
  • Contact

Design and develop by 2020 name. 2020 name

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home

Design and develop by 2020 name. 2020 name