CVE-2017-16020

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
References
Link Resource
https://nodesecurity.io/advisories/315 Third Party Advisory
https://github.com/notduncansmith/summit/issues/23 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:summit_project:summit:*:*:*:*:*:node.js:*:*

Information

Published : 2018-06-04 12:29

Updated : 2019-10-09 16:24


NVD link : CVE-2017-16020

Mitre link : CVE-2017-16020


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

summit_project

  • summit