Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26707

Опубликовано: 02 июн. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:merge-deep_project:merge-deep:*:*:*:*:*:node.js:*:*
Версия до 3.0.3 (исключая)
Конфигурация 2
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.0109
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
redhat
около 5 лет назад

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

CVSS3: 9.8
github
больше 4 лет назад

Prototype pollution in Merge-deep

EPSS

Процентиль: 78%
0.0109
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-1321