Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10746

Опубликовано: 23 авг. 2019
Источник: debian
EPSS Низкий

Описание

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-mixin-deepfixed2.0.1-1package
node-mixin-deepfixed1.1.3-3+deb10u1busterpackage
node-mixin-deepfixed1.1.3-1+deb9u1stretchpackage

Примечания

  • https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212

  • https://github.com/jonschlinkert/mixin-deep/commit/8f464c8ce9761a8c9c2b3457eaeee9d404fa7af9

  • https://github.com/jonschlinkert/mixin-deep/issues/6

EPSS

Процентиль: 73%
0.0081
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 7
redhat
около 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 9.8
nvd
почти 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 9.8
github
почти 6 лет назад

Prototype Pollution in mixin-deep

oracle-oval
больше 4 лет назад

ELSA-2021-0549: nodejs:12 security update (MODERATE)

EPSS

Процентиль: 73%
0.0081
Низкий