GHSA-4gxf-g5gf-22h4

Suggest an improvement
Source
https://github.com/advisories/GHSA-4gxf-g5gf-22h4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-4gxf-g5gf-22h4/GHSA-4gxf-g5gf-22h4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4gxf-g5gf-22h4
Aliases
Published
2023-06-10T06:30:25Z
Modified
2023-11-08T04:11:59.312591Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
dottie vulnerable to Prototype Pollution
Details

Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.

References

Affected packages

npm / dottie

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.4

Ecosystem specific

{
    "affected_functions": [
        "(dottie).set"
    ]
}