Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25645

Опубликовано: 01 мая 2022
Источник: nvd
CVSS3: 6.5
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains proto, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dset_project:dset:*:*:*:*:*:node.js:*:*

EPSS

Процентиль: 71%
0.00697
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.5
redhat
больше 3 лет назад

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
github
больше 3 лет назад

Prototype Pollution in dset

EPSS

Процентиль: 71%
0.00697
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-1321