Описание
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “proto”.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.0.11 (включая)
cpe:2.3:a:underscore-keypath_project:underscore-keypath:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 33%
0.00127
Низкий
7.5 High
CVSS3
Дефекты
CWE-1321
CWE-1321
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
underscore-keypath vulnerable to Prototype Pollution
EPSS
Процентиль: 33%
0.00127
Низкий
7.5 High
CVSS3
Дефекты
CWE-1321
CWE-1321