GHSA-36c4-4r89-6whg

Suggest an improvement
Source
https://github.com/advisories/GHSA-36c4-4r89-6whg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-36c4-4r89-6whg/GHSA-36c4-4r89-6whg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-36c4-4r89-6whg
Published
2020-09-03T15:49:02Z
Modified
2021-10-04T21:05:01Z
Summary
Prototype Pollution in @commercial/subtext
Details

Versions of @commercial/subtext prior to 5.1.2 are vulnerable to Prototype Pollution. A multipart payload can be constructed in a way that one of the parts’ content can be set as the entire payload object’s prototype. If this prototype contains data, it may bypass other validation rules which enforce access and privacy. If this prototype evaluates to null, it can cause unhandled exceptions when the request payload is accessed.

Recommendation

Upgrade to version 5.1.2 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-1321"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T19:01:00Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @commercial/subtext

Package

Name
@commercial/subtext
View open source insights on deps.dev
Purl
pkg:npm/%40commercial/subtext

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-36c4-4r89-6whg/GHSA-36c4-4r89-6whg.json"