Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37598

Опубликовано: 20 окт. 2022
Источник: debian
EPSS Низкий

Описание

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
uglify-jsunfixedpackage
uglifyjsremovedpackage

Примечания

  • https://github.com/mishoo/UglifyJS/issues/5699

  • Issue is not considered valid from upstream in

  • https://github.com/mishoo/UglifyJS/issues/5721#issuecomment-1292849604

EPSS

Процентиль: 74%
0.00796
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

CVSS3: 9.8
redhat
больше 3 лет назад

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

CVSS3: 9.8
nvd
больше 3 лет назад

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

CVSS3: 9.8
github
больше 3 лет назад

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js.

EPSS

Процентиль: 74%
0.00796
Низкий