CVE-2020-7677
published 2022-07-25CVE-2020-7677: This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.64%
73.7th percentile
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-thenify | < node-thenify 3.3.1-1 (bookworm) | node-thenify 3.3.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| thenify_project | thenify | < 3.3.1 | 3.3.1 |
| thenify_project | thenify | >= 0 < 3.3.1 | 3.3.1 |
| thenify_project | thenify | >= unspecified < 3.3.1 | 3.3.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
thenify vulnerability
vendor_ubuntu·2023-04-13
CVE-2020-7677 thenify vulnerability
Title: thenify vulnerability
Summary: A security issue weas fixed in thenify.
It was discovered that thenify incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
thenify: Arbitrary Code Execution in thenify
vendor_redhat·2022-07-25·CVSS 8.6
CVE-2020-7677 [HIGH] CWE-78 thenify: Arbitrary Code Execution in thenify
thenify: Arbitrary Code Execution in thenify
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
A flaw was found in the thenify package. Users can control the name argument provided to the package without any sanitization, and this is provided to the eval function without any sanitization, which leads to arbitrary code execution.
Statement: Red Hat Service Registry does not directly use the vulnerable code, but has a dependency on the affected package, and as such is affected at Low impact.
Red Hat Service Mesh (OSSM) is closed as Won't Do as Thenify is hosted only by Cucumber, which is a development dependency for automation test
Debian
CVE-2020-7677: node-thenify - This affects the package thenify before 3.3.1. The name argument provided to the...
vendor_debian·2020·CVSS 8.6
CVE-2020-7677 [HIGH] CVE-2020-7677: node-thenify - This affects the package thenify before 3.3.1. The name argument provided to the...
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
Scope: local
bookworm: resolved (fixed in 3.3.1-1)
bullseye: resolved (fixed in 3.3.1-1)
forky: resolved (fixed in 3.3.1-1)
sid: resolved (fixed in 3.3.1-1)
trixie: resolved (fixed in 3.3.1-1)
OSV
CVE-2020-7677: This affects the package thenify before 3
osv·2022-07-25·CVSS 9.8
CVE-2020-7677 [CRITICAL] CVE-2020-7677: This affects the package thenify before 3
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
GHSA
thenify before 3.3.1 made use of unsafe calls to `eval`.
ghsa·2022-07-18
CVE-2020-7677 [CRITICAL] CWE-78 thenify before 3.3.1 made use of unsafe calls to `eval`.
thenify before 3.3.1 made use of unsafe calls to `eval`.
Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.
OSV
thenify before 3.3.1 made use of unsafe calls to `eval`.
osv·2022-07-18
CVE-2020-7677 [CRITICAL] thenify before 3.3.1 made use of unsafe calls to `eval`.
thenify before 3.3.1 made use of unsafe calls to `eval`.
Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/thenables/thenify/blob/master/index.js%23L17https://github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17ahttps://lists.debian.org/debian-lts-announce/2022/09/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317https://security.snyk.io/vuln/SNYK-JS-THENIFY-571690https://github.com/thenables/thenify/blob/master/index.js%23L17https://github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17ahttps://lists.debian.org/debian-lts-announce/2022/09/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317https://security.snyk.io/vuln/SNYK-JS-THENIFY-571690
2022-07-25
Published