Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc58-wgmc-hfjr

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Prototype Pollution in mout

This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.

Пакеты

Наименование

mout

npm
Затронутые версииВерсия исправления

< 1.2.3

1.2.3

EPSS

Процентиль: 76%
0.00982
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.

EPSS

Процентиль: 76%
0.00982
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321