Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9cm-qmx5-m98h

Опубликовано: 01 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Prototype Pollution in merge

Versions of merge before 1.2.1 are vulnerable to prototype pollution. The merge.recursive function can be tricked into adding or modifying properties of the Object prototype.

Recommendation

Update to version 1.2.1 or later.

Пакеты

Наименование

merge

npm
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 61%
0.00408
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack.

CVSS3: 7.5
nvd
больше 7 лет назад

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack.

EPSS

Процентиль: 61%
0.00408
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321
CWE-400