Описание
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:rangy_project:rangy:-:*:*:*:*:node.js:*:*
EPSS
Процентиль: 23%
0.00079
Низкий
7.5 High
CVSS3
8.2 High
CVSS3
Дефекты
CWE-1321
CWE-1321
CWE-1321
Связанные уязвимости
EPSS
Процентиль: 23%
0.00079
Низкий
7.5 High
CVSS3
8.2 High
CVSS3
Дефекты
CWE-1321
CWE-1321
CWE-1321