peter bassill · operator
$ cve CVE-2014-7205 JSON

CVE-2014-7205 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 78.6% (pctl 100)

Patch early

A public exploit exists.

Description

Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS78.58% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-10-08
Last modified2026-06-17

Affected (1)

VendorProduct
bassmaster projectbassmaster

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD