Логотип exploitDog
bind:CVE-2023-45827
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-45827

Количество 3

Количество 3

nvd логотип

CVE-2023-45827

больше 2 лет назад

Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-9w5f-mw3p-pj47

больше 2 лет назад

Prototype Pollution(PP) vulnerability in setByPath

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2024-01227

больше 2 лет назад

Уязвимость библиотеки dot-diver, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-45827

Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.

CVSS3: 7.3
8%
Низкий
больше 2 лет назад
github логотип
GHSA-9w5f-mw3p-pj47

Prototype Pollution(PP) vulnerability in setByPath

CVSS3: 7.3
8%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-01227

Уязвимость библиотеки dot-diver, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
8%
Низкий
больше 2 лет назад

Уязвимостей на страницу