serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Serialize-javascript | Verizon | * | 3.1.0 (excluding) |
OpenShift Service Mesh 1.0 | RedHat | servicemesh-grafana-0:6.2.2-38.el8 | * |
OpenShift Service Mesh 1.1 | RedHat | servicemesh-grafana-0:6.4.3-11.el8 | * |