Eval injection vulnerability in the internals.batch function in lib/batch.js in...
Vulnerability Description
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-7205
Credits & Attribution
No credits recorded in the NVD database.
References
- https://nodesecurity.io/advisories/bassmaster_js_injection
- http://www.openwall.com/lists/oss-security/2014/09/30/10
- http://www.securityfocus.com/bid/70180
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96730
- https://www.exploit-db.com/exploits/40689/
- https://github.com/hapijs/bassmaster/commit/b751602d8cb7194ee62a61e085069679525138c4
Affected Vendor
bassmaster project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.