Описание
Prototype Pollution in putil-merge
Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.
Пакеты
Наименование
putil-merge
npm
Затронутые версииВерсия исправления
>= 1.0.0, <= 3.6.6
3.7.0
Связанные уязвимости
CVSS3: 9.8
nvd
больше 4 лет назад
Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.