CVE-2018-3749 – deap
Package
Manager: npm
Name: deap
Vulnerable Version: >=0 <1.0.1
Severity
Level: Critical
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00332 pctl0.55449
Details
Improper Input Validation in Deap The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
Metadata
Created: 2022-05-14T03:05:46Z
Modified: 2022-06-28T23:46:37Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xg47-r67p-vhv5/GHSA-xg47-r67p-vhv5.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-xg47-r67p-vhv5
Finding: F184
Auto approve: 1