Логотип exploitDog
bind:CVE-2022-25354
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25354

Количество 2

Количество 2

nvd логотип

CVE-2022-25354

почти 4 года назад

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-6956-83fg-5wc5

почти 4 года назад

Prototype Pollution in set-in

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-25354

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)

CVSS3: 8.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-6956-83fg-5wc5

Prototype Pollution in set-in

CVSS3: 9.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу