{"id":"GHSA-v726-3vg9-cp34","summary":"Missing Authorization in FastReport","details":"An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.","aliases":["CVE-2020-27998"],"modified":"2023-11-08T04:03:22.735705Z","published":"2021-08-02T17:28:16Z","database_specific":{"nvd_published_at":"2020-10-29T18:15:00Z","cwe_ids":["CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-07-26T18:29:52Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27998"},{"type":"WEB","url":"https://github.com/FastReports/FastReport/pull/206"},{"type":"WEB","url":"https://github.com/FastReports/FastReport/compare/v2020.3.0...v2020.4.0"},{"type":"WEB","url":"https://opensource.fast-report.com/2020/09/report-script-security.html"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2020-143-FastReportsInc-FastReports"}],"affected":[{"package":{"name":"FastReport.OpenSource","ecosystem":"NuGet","purl":"pkg:nuget/FastReport.OpenSource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2020.4.0"}]}],"versions":["2018.4.16","2018.4.7","2018.4.9","2019.1.0","2019.1.20","2019.2.0","2019.3.0","2019.3.13","2019.3.19","2020.1.20","2020.1.25","2020.1.28","2020.2.0","2020.2.9","2020.3.0","2020.3.1","2020.3.10","2020.3.14","2020.3.17","2020.3.21","2020.3.22","2020.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-v726-3vg9-cp34/GHSA-v726-3vg9-cp34.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}