CVE-2018-3753 – merge-object
Package
Manager: npm
Name: merge-object
Vulnerable Version: >=0 <=1.0.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00332 pctl0.55449
Details
Prototype Pollution in async merge-object The utilities function in all versions of the merge-object node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
Metadata
Created: 2018-09-18T13:47:24Z
Modified: 2022-04-26T20:44:24Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-fp82-2h99-3fpp/GHSA-fp82-2h99-3fpp.json
CWE IDs: ["CWE-1321", "CWE-20"]
Alternative ID: GHSA-fp82-2h99-3fpp
Finding: F390
Auto approve: 1