Vulnerability Database
Blog
FAQ
Docs
GHSA-wgfq-7857-4jcc
Suggest an improvement
Source
https://github.com/advisories/GHSA-wgfq-7857-4jcc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-wgfq-7857-4jcc/GHSA-wgfq-7857-4jcc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wgfq-7857-4jcc
Aliases
CVE-2020-8237
Published
2021-05-07T16:47:19Z
Modified
2023-11-08T04:04:15.903445Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Uncontrolled Resource Consumption in json-bigint
Details
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
References
https://nvd.nist.gov/vuln/detail/CVE-2020-8237
https://hackerone.com/reports/916430
Affected packages
npm
/
json-bigint
Package
Name
json-bigint
View open source insights on deps.dev
Purl
pkg:npm/json-bigint
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.0.0
GHSA-wgfq-7857-4jcc - OSV