Логотип exploitDog
bind:CVE-2022-25645
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25645

Количество 3

Количество 3

redhat логотип

CVE-2022-25645

больше 3 лет назад

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-25645

больше 3 лет назад

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23wx-cgxq-vpwx

больше 3 лет назад

Prototype Pollution in dset

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-25645

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-25645

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23wx-cgxq-vpwx

Prototype Pollution in dset

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу