The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96410 | vdb entry third party advisory |
https://nodesecurity.io/advisories/39 | exploit patch vendor advisory |
http://www.openwall.com/lists/oss-security/2016/04/20/11 | third party advisory mailing list |