Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr2v-3952-633q

Опубликовано: 09 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Prototype Pollution in deep-extend

Versions of deep-extend before 0.5.1 are vulnerable to prototype pollution.

Recommendation

Update to version 0.5.1 or later.

Пакеты

Наименование

deep-extend

npm
Затронутые версииВерсия исправления

< 0.5.1

0.5.1

EPSS

Процентиль: 60%
0.00405
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 4.2
redhat
около 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
nvd
около 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
debian
около 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend nod ...

rocky
больше 4 лет назад

Moderate: nodejs:12 security update

EPSS

Процентиль: 60%
0.00405
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20