Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8g4m-cjm2-96wq

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Sandbox escape in notevil and argencoders-notevil

This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878. This package has been deprecated.

Пакеты

Наименование

notevil

npm
Затронутые версииВерсия исправления

<= 1.3.3

Отсутствует

Наименование

argencoders-notevil

npm
Затронутые версииВерсия исправления

<= 2.5.0

Отсутствует

EPSS

Процентиль: 53%
0.00304
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. **Note:** This vulnerability derives from an incomplete fix in [SNYK-JS-NOTEVIL-608878](https://security.snyk.io/vuln/SNYK-JS-NOTEVIL-608878).

EPSS

Процентиль: 53%
0.00304
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321