Fortify Vulnerability Dynamic Code Evaluation: Code Injection in jsrender.js file

Questions : Fortify Vulnerability Dynamic Code Evaluation: Code Injection in jsrender.js file


There is a security vulnerability that I am trying to mitigate. The vulnerability was found in a third party Javascript file. Below is the line of code that the Fortity scan has pointed to, and when I checked about it, I found that the use of function() constructor could be vulnerable to code injection.

code = new Function("data, view, j, b, _OFFSET);  u", code);

I see that there is no higher version of the nuget package where this issue had been fixed. I cannot simply replace the code because it is a third party library. Can someone please provide some inputs on what could be the best possible options to resolve this before one can consider a risk deferral.

Total Answers 0

