VDB
BDU%3A2024-04404
BDU%3A2024-04404
PUBLISHED
CVSS 7.599999904632568 HIGH
Уязвимость функций compileClient, compileFileClient и compileClientWithDependenciesTracked шаблонизатора для создания HTML-разметки Pug (ранее Jade), позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
7.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения | Pug, pug-code-gen |
Timeline
- Jun 7, 2024 CVE Published
References
- https://github.com/pugjs/pug/pull/3428 url
- https://github.com/advisories/GHSA-3965-hpx2-q597 url
- https://github.com/pugjs/pug/pull/3438 url
- https://github.com/Coding-Competition-Team/hackac-2024/tree/main/web/pug url
- https://github.com/pugjs/pug/blob/4767cafea0af3d3f935553df0f9a8a6e76d470c2/packages/pug/lib/index.js#L328 url
- https://github.com/pugjs/pug/commit/32acfe8f197dc44c54e8af32c7d7b19aa9d350fb url
- https://github.com/pugjs/pug/releases/tag/pug%403.0.3 url
- https://pugjs.org/api/reference.html url
- https://www.npmjs.com/package/pug-code-gen?activeTab=readme url