CVE Database
/

CVE-2016-10546

Back to search

CVE-2016-10546

Published: May 31, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used to run arbitrary JavaScript as well as system commands.

VendorProductVersions

HackerOne

pouchdb node module

affected
<=6.0.4

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now