Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79jw-6wg7-r9g4

Опубликовано: 06 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Use of Potentially Dangerous Function in mixme

Impact

In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

Patches

The problem is corrected starting with version 0.5.1.

References

Issue: https://github.com/adaltas/node-mixme/issues/1 Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028

Пакеты

Наименование

mixme

npm
Затронутые версииВерсия исправления

< 0.5.1

0.5.1

7.1 High

CVSS3

Дефекты

CWE-913

Связанные уязвимости

nvd
почти 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28860. Reason: This candidate is a reservation duplicate of CVE-2021-28860. Notes: All CVE users should reference CVE-2021-28860 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

7.1 High

CVSS3

Дефекты

CWE-913