Описание
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the Object.prototype. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by express-mock-middleware. As such, this is considered to be a low risk.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.0.6 (включая)
cpe:2.3:a:express-mock-middleware_project:express-mock-middleware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00318
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1321
Связанные уязвимости
CVSS3: 5.3
github
около 4 лет назад
Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware
EPSS
Процентиль: 54%
0.00318
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1321