GHSA-p23c-p8w2-ww5v

Source
https://github.com/advisories/GHSA-p23c-p8w2-ww5v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-p23c-p8w2-ww5v/GHSA-p23c-p8w2-ww5v.json
Aliases
  • CVE-2022-25871
Published
2022-06-18T00:00:19Z
Modified
2023-11-08T04:08:50.153834Z
Details

All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of CVE-2020-7600.

References

Affected packages

npm / querymen

Package

Name
querymen

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
2.1.4