Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c2g-hx49-7h25

Опубликовано: 23 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Prototype pollution not blocked by object-path related utilities in hoolock

Impact

Utility functions related to object paths (get, set and update) did not block attempts to access or alter object prototypes.

Patches

The get, set and update functions will throw a TypeError when a user attempts to access or alter inherited properties in versions >=2.2.1.

Пакеты

Наименование

hoolock

npm
Затронутые версииВерсия исправления

>= 2.0.0, < 2.2.1

2.2.1

EPSS

Процентиль: 93%
0.09783
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 лет назад

hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object paths (`get`, `set`, and `update`) did not block attempts to access or alter object prototypes. Starting in version 2.2.1, the `get`, `set` and `update` functions throw a `TypeError` when a user attempts to access or alter inherited properties.

EPSS

Процентиль: 93%
0.09783
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-1321