High severity8.6NVD Advisory· Published Jul 25, 2022· Updated Jun 17, 2026
CVE-2020-7677
CVE-2020-7677
Description
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
thenifynpm | < 3.3.1 | 3.3.1 |
org.webjars.npm:thenifyMaven | < 3.3.1 | 3.3.1 |
Affected products
6cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 3.3.1+ 1 more
- (no CPE)range: < 3.3.1
- (no CPE)range: < 3.3.1
Patches
Vulnerability mechanics
References
12- github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17anvdPatchWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317nvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-THENIFY-571690nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-29xr-v42j-r956ghsaADVISORY
- lists.debian.org/debian-lts-announce/2022/09/msg00039.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-7677ghsaADVISORY
- github.com/thenables/thenify/blob/master/index.js%23L17nvdBroken LinkWEB
- github.com/thenables/thenify/issues/29ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLKghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK/nvd
News mentions
0No linked articles in our index yet.