Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhjf-83wg-r2j9

Опубликовано: 27 авг. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Prototype Pollution in mixin-deep

Versions of mixin-deep prior to 2.0.1 or 1.3.2 are vulnerable to Prototype Pollution. The mixinDeep function fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.

Recommendation

If you are using mixin-deep 2.x, upgrade to version 2.0.1 or later. If you are using mixin-deep 1.x, upgrade to version 1.3.2 or later.

Пакеты

Наименование

mixin-deep

npm
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

Наименование

mixin-deep

npm
Затронутые версииВерсия исправления

= 2.0.0

2.0.1

EPSS

Процентиль: 59%
0.00378
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 7
redhat
около 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 9.8
nvd
почти 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVSS3: 9.8
debian
почти 6 лет назад

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3 ...

oracle-oval
больше 4 лет назад

ELSA-2021-0549: nodejs:12 security update (MODERATE)

EPSS

Процентиль: 59%
0.00378
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88