Vulnerability Name:

CVE-2014-7192 (CCN-96728)

Assigned:2014-09-30
Published:2014-09-30
Updated:2017-09-08
Summary:Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-7192

Source: CCN
Type: Node.js Web site
node.js

Source: CCN
Type: IBM Security Bulletin 1690815
Multiple vulnerabilities in modules from the IBM SDK for Node.js affect the Cordova tools in IBM Rational Application Developer (CVE-2014-7191 and CVE-2014-7192)

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg21690815

Source: CCN
Type: IBM Security Bulletin 1686792
Multiple vulnerabilities affecting the Cordova platform and IBM SDK Node.js packaged with Rational Software Architect and Rational Software Architect for WebSphere Software

Source: CCN
Type: IBM Security Bulletin 1692460
Multiple vulnerabilities in modules from the IBM SDK for Node.js affect the Cordova tools packaged in Rational Developer for i Modernization Tools Java Edition and Rational Developer for AIX and Linux (CVE-2014-7191 and CVE-2014-7192)

Source: CCN
Type: oss-security Mailing List, Tue, 30 Sep 2014 00:53:42 -0400 (EDT)
Re: CVE request: various NodeJS module vulnerabilities

Source: CCN
Type: BID-70105
Node.js syntax-error module 'eval()' Function Arbitrary Code Execution Vulnerability

Source: XF
Type: UNKNOWN
nodejs-cve20147192-code-exec(96728)

Source: XF
Type: UNKNOWN
nodejs-cve20147192-code-exec(96728)

Source: CONFIRM
Type: Exploit
https://github.com/substack/node-syntax-error/commit/9aa4e66eb90ec595d2dba55e6f9c2dd9a668b309

Source: CCN
Type: Node Security Web site
syntax-error potential for script injection

Source: CONFIRM
Type: Vendor Advisory
https://nodesecurity.io/advisories/syntax-error-potential-script-injection

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-7192

Vulnerable Configuration:Configuration 1:
  • cpe:/a:joyent:node.js:*:*:*:*:*:*:*:* (Version <= 0.10.32)

  • Configuration CCN 1:
  • cpe:/a:nodejs:node.js:0.10.18:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:rational_application_developer:9.1:*:*:*:websphere:*:*:*
  • OR cpe:/a:ibm:rational_application_developer:9.1.0.1:*:*:*:websphere:*:*:*
  • OR cpe:/a:ibm:rational_application_developer:9.1.1:*:*:*:websphere:*:*:*
  • OR cpe:/a:ibm:rational_software_architect:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_software_architect:9.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_developer_for_i:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:nodejs:node.js:*:*:*:*:-:*:*:*

  • * Denotes that component is vulnerable
    BACK
    joyent node.js *
    nodejs node.js 0.10.18
    ibm rational application developer 9.1
    ibm rational application developer 9.1.0.1
    ibm rational application developer 9.1.1
    ibm rational software architect 9.1
    ibm rational software architect 9.1.1
    ibm rational developer for i 9.1
    nodejs node.js *