UBUNTU-CVE-2020-28502
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-28502
Summary:
Details: This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
References: https://ubuntu.com/security/CVE-2020-28502, https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUEST-1082935, https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936, https://github.com/driverdan/node-XMLHttpRequest/blob/1.6.0/lib/XMLHttpRequest.js%23L480, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1082937, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1082938, https://www.cve.org/CVERecord?id=CVE-2020-28502
Affected packages
Package
Name: node-xmlhttprequest
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
