GHSA-22h7-7wwg-qmgg

Suggest an improvement
Source
https://github.com/advisories/GHSA-22h7-7wwg-qmgg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-22h7-7wwg-qmgg/GHSA-22h7-7wwg-qmgg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-22h7-7wwg-qmgg
Published
2020-09-04T17:56:39Z
Modified
2020-08-31T19:00:24Z
Summary
Prototype Pollution in @hapi/hoek
Details

Versions of @hapi/hoek prior to 8.5.1 and 9.0.3 are vulnerable to Prototype Pollution. The clone function fails to prevent the modification of the Object prototype when passed specially-crafted input. Attackers may use this to change existing properties that exist in all objects, which may lead to Denial of Service or Remote Code Execution in specific circumstances.
This issue does not affect hapi applications since the framework protects against such malicious inputs. Applications that use @hapi/hoek outside of the hapi ecosystem may be vulnerable.

Recommendation

Update to version 8.5.1, 9.0.3 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-1321"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T19:00:24Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / @hapi/hoek

Package

Name
@hapi/hoek
View open source insights on deps.dev
Purl
pkg:npm/%40hapi/hoek

Affected ranges

Type
SEMVER
Events
Introduced
8.3.2
Fixed
8.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-22h7-7wwg-qmgg/GHSA-22h7-7wwg-qmgg.json"

npm / @hapi/hoek

Package

Name
@hapi/hoek
View open source insights on deps.dev
Purl
pkg:npm/%40hapi/hoek

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-22h7-7wwg-qmgg/GHSA-22h7-7wwg-qmgg.json"