Executive brief
sailsjs-cacheman is a caching module for Node.js applications. A vulnerability allows the configuration variable to be exposed to the global scope, potentially overwriting other application variables and causing unexpected behavior. This could lead to application malfunctions or enable an attacker to corrupt the runtime state of the application.
Technical details
The vulnerability is a variable scoping error in sailsjs-cacheman where the config variable is not properly declared with the `var` keyword, causing it to be exposed to the global scope. This allows the variable to overwrite other globally-scoped variables in the application, leading to undefined behavior and potential application crashes or malfunction. The fix is simple (adding `var` before the config assignment), but since the repository was archived, no official patch was released. Exploitation requires the module to be loaded in an application where such global variable collisions can occur. This is a low-severity issue as it primarily affects application stability rather than providing a direct security exploit path.
Affected products
- gayanhewa sailsjs-cacheman 0.0.0 to 1.0.0
Timeline
- 2019-09-11: disclosed