Количество 2
Количество 2
CVE-2021-28860
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
GHSA-r5cq-9537-9rpf
Prototype Pollution in mixme
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-28860 In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS). | CVSS3: 9.1 | 1% Низкий | почти 5 лет назад | |
GHSA-r5cq-9537-9rpf Prototype Pollution in mixme | CVSS3: 9.1 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу