math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.
References
Link | Resource |
---|---|
https://github.com/josdejong/mathjs/commit/a60f3c8d9dd714244aed7a5569c3dccaa3a4e761 | Patch Third Party Advisory |
https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170 | Third Party Advisory |
Configurations
Information
Published : 2017-11-27 06:29
Updated : 2019-10-09 16:21
NVD link : CVE-2017-1001003
Mitre link : CVE-2017-1001003
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mathjs_project
- mathjs