Описание
sassdoc-extras vulnerable to prototype pollution
A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
Пакеты
Наименование
sassdoc-extras
npm
Затронутые версииВерсия исправления
<= 3.0.0
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
5 месяцев назад
A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.