Описание
depath and cool-path vulnerable to Prototype Pollution via set() Method
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Пакеты
Наименование
depath
npm
Затронутые версииВерсия исправления
<= 1.0.6
Отсутствует
Наименование
cool-path
npm
Затронутые версииВерсия исправления
<= 1.1.2
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
11 месяцев назад
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.