Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g8m-v378-pcg3

Опубликовано: 24 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

parse is vulnerable to prototype pollution

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Пакеты

Наименование

parse

npm
Затронутые версииВерсия исправления

< 7.0.0-alpha.1

7.0.0-alpha.1

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321