CVE-2020-28450 is a high-severity vulnerability (CVSS 8.6) affecting all versions of the 'decal' package, specifically within its 'extend' function. This flaw allows an unauthenticated attacker to remotely compromise the system with low attack complexity, potentially leading to partial confidentiality, integrity, and complete availability impacts. While no public exploits or Metasploit modules are available, and community discussion is minimal, organizations using the 'decal' package should still address this vulnerability due to its high potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:decal_project:decal:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.