anistark / anistark/commenting-react

arbitrary code execution

未關閉
#1 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
JavaScript
星號
0
分支
1
PR 合併指標
30 天內沒有已合併 PR

描述

less.js is vulnerable to arbitrary code execution. An attacker can execute arbitrary shell command during compilation by passing less code that contains malicious embedded JavaScript code to the compiler. This vulnerability can be exploited in various scenarios. 1) An application takes user-input and feeds it to the less compiler. In this case an attacker can compromise the system. 2) A user downloads and compiles a malicious LESS file. These situtations allow a malicious user to compromise the user's system.

## The Fix

This vulnerability is in a direct dependency. Vulnerable library less was found in package.json It can be fixed by updating the version of the library in your project and rebuilding it.

To update your package.json file, run the following command

npm install less@3.0.0-pre.1 --save

package.json

```
"dependencies": {
 ···
− "less": "2.7.1",
+ "less": "3.0.0-pre.1",
 ···
}
```

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。