Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16472

Опубликовано: 06 нояб. 2018
Источник: debian

Описание

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-cached-path-relativefixed1.0.2-1package

Примечания

  • https://hackerone.com/reports/390847

  • https://github.com/ashaffer/cached-path-relative/issues/3

  • Fixed by: https://github.com/ashaffer/cached-path-relative/commit/a43cffec84ed0e9eceecb43b534b6937a8028fc0

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 5.3
redhat
больше 7 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 7.5
nvd
больше 7 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 7.5
github
около 7 лет назад

Prototype Pollution in cached-path-relative