Описание
Prototype Pollution in node-forge
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: version 0.10.0 is a breaking change removing the vulnerable functions.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-7720
- https://github.com/digitalbazaar/forge/commit/6a1e3ef74f6eb345bcff1b82184201d1e28b6756
- https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md
- https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md#removed
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
Пакеты
node-forge
< 0.10.0
0.10.0
Связанные уязвимости
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
The package node-forge before 0.10.0 is vulnerable to Prototype Pollut ...
Уязвимость функции util.setPath библиотеки node-fetch прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»