Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-3719

Опубликовано: 07 июн. 2018
Источник: debian
EPSS Низкий

Описание

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-mixin-deepfixed1.1.3-2package
node-mixin-deepfixed1.1.3-1+deb9u1stretchpackage

Примечания

  • https://nodesecurity.io/advisories/578

EPSS

Процентиль: 70%
0.00639
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 3.3
redhat
почти 8 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 8.8
nvd
больше 7 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 8.8
github
больше 7 лет назад

Prototype Pollution in mixin-deep

EPSS

Процентиль: 70%
0.00639
Низкий