Описание
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
EPSS
Процентиль: 25%
0.00336
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 7.3
github
4 месяца назад
Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
EPSS
Процентиль: 25%
0.00336
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94