Описание
confinit vulnerable to prototype pollution
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a 'proto' payload.
Пакеты
Наименование
confinit
npm
Затронутые версииВерсия исправления
< 0.4.0
0.4.0
Связанные уязвимости
CVSS3: 5.3
nvd
почти 6 лет назад
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.