CVE-2015-8857

CRITICAL9.8EPSS 0.27%

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

發布日:2017/10/24修改日:2026/4/28

描述

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)