Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45rm-2893-5f49

Опубликовано: 22 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

liquidjs may leak properties of a prototype

The package liquidjs before 10.0.0 is vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.

Пакеты

Наименование

liquidjs

npm
Затронутые версииВерсия исправления

< 10.0.0

10.0.0

EPSS

Процентиль: 55%
0.0033
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.

EPSS

Процентиль: 55%
0.0033
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200