logo

CVE-2018-3753 merge-object

Package

Manager: npm
Name: merge-object
Vulnerable Version: >=0 <=1.0.0

Severity

Level: Critical

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00332 pctl0.55449

Details

Prototype Pollution in async merge-object The utilities function in all versions of the merge-object node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

Metadata

Created: 2018-09-18T13:47:24Z
Modified: 2022-04-26T20:44:24Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-fp82-2h99-3fpp/GHSA-fp82-2h99-3fpp.json
CWE IDs: ["CWE-1321", "CWE-20"]
Alternative ID: GHSA-fp82-2h99-3fpp
Finding: F390
Auto approve: 1