{"id":"GHSA-g7rj-q722-245g","summary":"jsreport vulnerable to code injection","details":"jsreport prior to 3.11.3 had a version of vm2 vulnerable to CVE-2023-29017 hard coded in the package.json of the jsreport-core component. An attacker can use this vulnerability to obtain the authority of the jsreport playground server, or construct a malicious webpage/html file and send it to the user to attack the installed jsreport client.","aliases":["CVE-2023-2583"],"modified":"2023-11-08T04:11:56.301908Z","published":"2023-05-08T18:30:17Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-05-09T19:16:18Z","nvd_published_at":"2023-05-08T17:15:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2583"},{"type":"WEB","url":"https://github.com/jsreport/jsreport/commit/afaff3804b34b38e959f5ae65f9e672088de13d7"},{"type":"PACKAGE","url":"https://github.com/jsreport/jsreport"},{"type":"WEB","url":"https://github.com/jsreport/jsreport/releases/tag/3.11.3"},{"type":"WEB","url":"https://huntr.dev/bounties/397ea68d-1e28-44ff-b830-c8883d067d96"}],"affected":[{"package":{"name":"jsreport","ecosystem":"npm","purl":"pkg:npm/jsreport"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-g7rj-q722-245g/GHSA-g7rj-q722-245g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}