Описание
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "proto" payload.
A vulnerability was found in nodesjs-yargs-parser, where it can be tricked into adding or modifying properties of the Object.prototype using a "proto" payload. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
yargs-parser could be tricked into adding or modifying properties of O ...
Уязвимость библиотеки yargs-parser прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»
EPSS
5.3 Medium
CVSS3