Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
References
Link | Resource |
---|---|
https://vuln.ryotak.me/advisories/58 | Third Party Advisory |
https://github.com/denoland/deno_std/releases/tag/0.107.0 | Release Notes Third Party Advisory |
https://github.com/denoland/deno_std/pull/1275 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-10-10 22:15
Updated : 2021-11-04 05:47
NVD link : CVE-2021-42139
Mitre link : CVE-2021-42139
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
deno
- deno_standard_modules