Описание
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.
Ссылки
- Broken Link
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Broken Link
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6.2 (исключая)
cpe:2.3:a:algolia:algoliasearch-helper:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 58%
0.00367
Низкий
5.9 Medium
CVSS3
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-1321
Связанные уязвимости
EPSS
Процентиль: 58%
0.00367
Низкий
5.9 Medium
CVSS3
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-1321