Beveiligingsadvies

CVE-2020-28439

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-12-11 16:55:21
Laatst bijgewerkt 2024-09-16 19:56:43
Toegewezen door snyk
CVSS-score 9.8
Status PUBLISHED

Beschrijving

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC: