{"id":"GHSA-h4j5-c7cj-74xg","summary":"xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection","details":"This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (`async=False` on `xhr.open`), malicious user input flowing into `xhr.send` could result in arbitrary code being injected and run.","aliases":["CVE-2020-28502"],"modified":"2025-01-08T07:27:06.230818Z","published":"2021-05-04T18:02:34Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-03-18T20:34:02Z","nvd_published_at":"2021-03-05T18:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28502"},{"type":"WEB","url":"https://github.com/driverdan/node-XMLHttpRequest/commit/983cfc244c7567ad6a59e366e55a8037e0497fe6"},{"type":"WEB","url":"https://github.com/mjwwit/node-XMLHttpRequest/commit/ee1e81fc67729c7c0eba5537ed7fe1e30a6b3291"},{"type":"WEB","url":"https://github.com/driverdan/node-XMLHttpRequest/blob/1.6.0/lib/XMLHttpRequest.js#L480"},{"type":"WEB","url":"https://github.com/driverdan/node-XMLHttpRequest/blob/1.6.0/lib/XMLHttpRequest.js%23L480"},{"type":"WEB","url":"https://github.com/mjwwit/node-XMLHttpRequest/blob/ae38832a0f1347c5e96dda665402509a3458e302/lib/XMLHttpRequest.js#L531"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1082937"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1082938"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUEST-1082935"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936"}],"affected":[{"package":{"name":"xmlhttprequest","ecosystem":"npm","purl":"pkg:npm/xmlhttprequest"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-h4j5-c7cj-74xg/GHSA-h4j5-c7cj-74xg.json"}},{"package":{"name":"xmlhttprequest-ssl","ecosystem":"npm","purl":"pkg:npm/xmlhttprequest-ssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-h4j5-c7cj-74xg/GHSA-h4j5-c7cj-74xg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}