CVE-2015-8857

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uglifyjs_project:uglifyjs:*:*:*:*:*:node.js:*:* 2.4.24 (excluding)