GHSA-3xph-cp8f-2229

Suggest an improvement
Source
https://github.com/advisories/GHSA-3xph-cp8f-2229
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-3xph-cp8f-2229/GHSA-3xph-cp8f-2229.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3xph-cp8f-2229
Aliases
Published
2021-12-10T20:31:32Z
Modified
2023-11-08T04:06:25.432401Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
Prototype Pollution in @fabiocaccamo/utils.js
Details

utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').

Database specific
{
    "nvd_published_at": "2021-12-08T17:15:00Z",
    "github_reviewed_at": "2021-12-09T18:05:12Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-1321"
    ]
}
References

Affected packages

npm / @fabiocaccamo/utils.js

Package

Name
@fabiocaccamo/utils.js
View open source insights on deps.dev
Purl
pkg:npm/%40fabiocaccamo/utils.js

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.17.2