Описание
TypeORM vulnerable to MAID and Prototype Pollution
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Пакеты
Наименование
typeorm
npm
Затронутые версииВерсия исправления
< 0.2.25
0.2.25
Связанные уязвимости
CVSS3: 9.8
nvd
больше 5 лет назад
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.