CVE-2017-5941: Deserialization of Untrusted Data
(updated )
An issue was discovered in the node-serialize package for Node.js.
Untrusted data passed into the unserialize()
function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
References
Detect and mitigate CVE-2017-5941 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →