CVE-2020-7748 – @tsed/core
Package
Manager: npm
Name: @tsed/core
Vulnerable Version: >=0 <5.65.7
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: 0.00555 pctl0.67138
Details
Prototype pollution in @tsed/core This affects the package @tsed/core before 5.65.7. This vulnerability relates to the `deepExtend` function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
Metadata
Created: 2021-05-10T19:07:56Z
Modified: 2023-09-05T22:45:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-77xq-cpvg-7xm2/GHSA-77xq-cpvg-7xm2.json
CWE IDs: ["CWE-1321", "CWE-915"]
Alternative ID: GHSA-77xq-cpvg-7xm2
Finding: F390
Auto approve: 1