Skip to content

Problem caused by static_eval  #46

Closed
@ByCnck

Description

@ByCnck

Can you tell to the devs to check this repository please

https://github.com/AschPlatform/asch/blob/ff97f3c1cf2bdfd95cbb337dad694cd3b7c69a34/src/utils/protobuf.js

Problem: Arbitrary Code Execution

They are using protocol-Buffers 3.1.6
This version have a issue becuse it use some outdated of static-eval
The Vulnerability is introduced through this way:
Protocol-buffers> [email protected][email protected][email protected]

Here is the commit to fix part of the problem in the github of static-eval
browserify/static-eval@c06f1b8

Further information of the problem:
https://maustin.net/articles/2017-10/static_eval
https://nodesecurity.io/advisories/548

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions