Записи eggjs
2 опубликованных записей вендора eggjs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2018-3786Proof of concept | A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command lineeggjs · egg-scripts · CWE-77 | Критическая9,8 | — | 12,3 % | 24 авг. 2018 г. |
39Наблюдать | CVE-2021-23568Эксплойта нет | The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.eggjs · extend2 · CWE-1321 | Критическая9,8 | — | 1,5 % | 10 янв. 2022 г. |
- CVE-2018-378643В плане
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line
КритическаяCVSS 9,8Proof of conceptEPSS 12 %eggjs · egg-scripts24 авг. 2018 г.
- CVE-2021-2356839Наблюдать
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eggjs · extend210 янв. 2022 г.