Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmpr-vc5q-h3jw

Опубликовано: 13 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of Resource to Wrong Sphere in valib

valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.

Пакеты

Наименование

valib

npm
Затронутые версииВерсия исправления

<= 2.0.0

Отсутствует

EPSS

Процентиль: 45%
0.00227
Низкий

7.5 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.

EPSS

Процентиль: 45%
0.00227
Низкий

7.5 High

CVSS3

Дефекты

CWE-668