Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9wq-pxpv-8p4v

Опубликовано: 11 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "proto") as an argument to the function.

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "proto") as an argument to the function.

EPSS

Процентиль: 38%
0.00165
Низкий

Связанные уязвимости

CVSS3: 9.1
redhat
больше 3 лет назад

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes

CVSS3: 9.1
nvd
больше 3 лет назад

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes

CVSS3: 9.1
debian
больше 3 лет назад

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earl ...

EPSS

Процентиль: 38%
0.00165
Низкий