Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6rj-9ch6-g264

Опубликовано: 07 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Prototype pollution in Merge-deep

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

Пакеты

Наименование

merge-deep

npm
Затронутые версииВерсия исправления

< 3.0.3

3.0.3

EPSS

Процентиль: 78%
0.0109
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
redhat
около 5 лет назад

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

CVSS3: 9.8
nvd
больше 4 лет назад

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

EPSS

Процентиль: 78%
0.0109
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321