Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g954-5hwp-pp24

Опубликовано: 28 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Prototype Pollution in protobufjs

The package protobufjs is vulnerable to Prototype Pollution, which can allow an attacker to add/modify properties of the Object.prototype. Versions after and including 6.10.0 until 6.10.3 and after and including 6.11.0 until 6.11.3 are vulnerable.

This vulnerability can occur in multiple ways:

  1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions
  2. by parsing/loading .proto files

Пакеты

Наименование

protobufjs

npm
Затронутые версииВерсия исправления

>= 6.11.0, < 6.11.3

6.11.3

Наименование

protobufjs

npm
Затронутые версииВерсия исправления

>= 6.10.0, < 6.10.3

6.10.3

EPSS

Процентиль: 62%
0.00422
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 8.2
redhat
больше 3 лет назад

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

CVSS3: 8.2
nvd
больше 3 лет назад

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

EPSS

Процентиль: 62%
0.00422
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321