Описание
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Broken Link
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Broken Link
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.0.0 (исключая)
cpe:2.3:a:liquidjs:liquidjs:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 55%
0.0033
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-200
CWE-200
Связанные уязвимости
EPSS
Процентиль: 55%
0.0033
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-200
CWE-200