[Bug 1232683] New: VUL-0: CVE-2024-21537: nodejs-electron: lilconfig: insecure usage of eval in the dynamicImport function
https://bugzilla.suse.com/show_bug.cgi?id=1232683 Bug ID: 1232683 Summary: VUL-0: CVE-2024-21537: nodejs-electron: lilconfig: insecure usage of eval in the dynamicImport function Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/426383/ OS: Other Status: NEW Severity: Major Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: camila.matos@suse.com QA Contact: security-team@suse.de CC: brunopitrus@hotmail.com, camila.matos@suse.com, security-team@suse.de, smash_bz@suse.de Blocks: 1232672 Target Milestone: --- Found By: Security Response Team Blocker: --- +++ This bug was initially created as a clone of Bug #1232672 +++ Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-21537 https://www.cve.org/CVERecord?id=CVE-2024-21537 https://github.com/antonk52/lilconfig/commit/2c68a1ab8764fc74acc46771e1ad39a... https://github.com/antonk52/lilconfig/pull/48 https://github.com/antonk52/lilconfig/releases/tag/v3.1.1 https://security.snyk.io/vuln/SNYK-JS-LILCONFIG-6263789 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1232683 https://bugzilla.suse.com/show_bug.cgi?id=1232683#c1 Camila Camargo de Matos <camila.matos@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|--- |INVALID Status|NEW |RESOLVED --- Comment #1 from Camila Camargo de Matos <camila.matos@suse.com> --- lilconfig (2.0.6) is a dependency for openSUSE:Factory/nodejs-electron. Version 2.0.6 of lilconfig, however, is not affected by the vulnerability being described in this bug, and, therefore, the bug can be closed. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com