Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9w3-g83q-m6hq

Опубликовано: 01 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Prototype Pollution in deepmerge-ts

deepmerge-ts is used to merge 2 or more objects respecting type information. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). A fix was released in version 4.0.2. Currently, there is no known workaround.

Пакеты

Наименование

deepmerge-ts

npm
Затронутые версииВерсия исправления

< 4.0.2

4.0.2

EPSS

Процентиль: 71%
0.00678
Низкий

8.1 High

CVSS3

Дефекты

CWE-1321
CWE-915

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.

EPSS

Процентиль: 71%
0.00678
Низкий

8.1 High

CVSS3

Дефекты

CWE-1321
CWE-915