« Volver al listado

CVE-2020-7609

Estado: ModificadaCrítica (9.8)—

node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7609",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "report@snyk.io",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "node-rules",
          "versions": [
            {
              "status": "affected",
              "version": "All versions including 3.0.0 and prior to 5.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-27T22:15:12.317",
  "references": [
    {
      "url": "https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C",
      "source": "report@snyk.io"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODERULES-560426",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832%2C",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODERULES-560426",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function \"fromJSON()\" can be controlled by users without any sanitization."
    },
    {
      "lang": "es",
      "value": "node-rules incluyendo versiones 3.0.0 y anteriores a 5.0.0, permite una inyección de comandos arbitrarios. Las reglas de argumento de la función \"fromJSON()\" pueden ser controladas por usuarios sin ningún saneamiento."
    }
  ],
  "lastModified": "2026-06-17T03:25:06.913",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:node-rules_project:node-rules:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78601348-9CAF-4DD1-ADFD-7DC02DA207FD",
              "versionEndExcluding": "5.0.0",
              "versionStartIncluding": "3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "report@snyk.io"
}