Security Advisory
CVE-2015-8857
9.8
CRITICAL
Vulnerability Description
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.
Published Date
January 23, 2017
Official Source
NIST NVD Advisory