This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization. https://security.snyk.io/vuln/SNYK-JS-THENIFY-571690 https://github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17a https://github.com/thenables/thenify/blob/master/index.js%23L17 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 2127349]
Created nodejs tracking bugs for this issue: Affects: epel-7 [bug 2127350] Created yarnpkg tracking bugs for this issue: Affects: fedora-all [bug 2127351]