CVE-2020-28439

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
11/12/2020
Last modified:
21/07/2021

Description

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:corenlp-js-prefab_project:corenlp-js-prefab:*:*:*:*:*:node.js:*:*


References to Advisories, Solutions, and Tools