Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16472

Опубликовано: 02 нояб. 2018
Источник: redhat
CVSS3: 5.3

Описание

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4nodejs-cached-path-relativeOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1649118nodejs-cached-path-relative: prototype pollution due to injected properties on Object.prototype

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 7.5
nvd
почти 8 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 7.5
debian
почти 8 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 ...

CVSS3: 7.5
github
почти 8 лет назад

Prototype Pollution in cached-path-relative

5.3 Medium

CVSS3