Security Advisory

CVE-2015-8857

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-23 21:00:00
Last updated 2024-08-06 08:29:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.