CVE-2017-1001004
CVE-2017-1001004
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Affected products
typed-function · typed-functionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →