Описание
Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like proto.
EPSS
Процентиль: 68%
0.00582
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321
CWE-1321
Связанные уязвимости
CVSS3: 7.3
github
10 месяцев назад
expand-object Vulnerable to Prototype Pollution via the expand() Function
EPSS
Процентиль: 68%
0.00582
Низкий
7.3 High
CVSS3
Дефекты
CWE-1321
CWE-1321