Логотип exploitDog
bind:CVE-2018-3753
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-3753

Количество 2

Количество 2

nvd логотип

CVE-2018-3753

больше 7 лет назад

The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fp82-2h99-3fpp

больше 7 лет назад

Prototype Pollution in async merge-object

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-3753

The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
github логотип
GHSA-fp82-2h99-3fpp

Prototype Pollution in async merge-object

CVSS3: 9.8
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу