Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gh8-hqwg-xf34

Опубликовано: 25 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Starcounter-Jack JSON-Patch Prototype Pollution vulnerability

A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 can address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.

Пакеты

Наименование

fast-json-patch

npm
Затронутые версииВерсия исправления

< 3.1.1

3.1.1

EPSS

Процентиль: 61%
0.00411
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.3
nvd
около 3 лет назад

A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 is able to address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 61%
0.00411
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321