Vulnerabilities > CVE-2017-5941 - Deserialization of Untrusted Data vulnerability in Node-Serialize Project Node-Serialize

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
node-serialize-project
CWE-502
critical
exploit available

Summary

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionNode.JS - 'node-serialize' Remote Code Execution. CVE-2017-5941. Remote exploit for Linux platform
idEDB-ID:45265
last seen2018-08-27
modified2017-02-08
published2017-02-08
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45265/
titleNode.JS - 'node-serialize' Remote Code Execution