logo

CVE-2018-3749 deap

Package

Manager: npm
Name: deap
Vulnerable Version: >=0 <1.0.1

Severity

Level: Critical

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00332 pctl0.55449

Details

Improper Input Validation in Deap The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

Metadata

Created: 2022-05-14T03:05:46Z
Modified: 2022-06-28T23:46:37Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xg47-r67p-vhv5/GHSA-xg47-r67p-vhv5.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-xg47-r67p-vhv5
Finding: F184
Auto approve: 1