Описание
Prototype pollution in controlled-merge
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Пакеты
Наименование
controlled-merge
npm
Затронутые версииВерсия исправления
>= 1.0.0, < 1.3.0
1.3.0
Связанные уязвимости
CVSS3: 7.5
nvd
около 5 лет назад
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.