CVE-2013-4660

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:js-yaml_project:js-yaml:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:*:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.6:*:*:*:*:*:*:*
cpe:2.3:a:js-yaml_project:js-yaml:0.3.7:*:*:*:*:*:*:*

Information

Published : 2013-06-28 07:55

Updated : 2013-07-01 07:51


NVD link : CVE-2013-4660

Mitre link : CVE-2013-4660


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

js-yaml_project

  • js-yaml