Prototype Pollution In canvg
Description
canvg Prototype Pollution vulnerability An issue in canvg prior to v.4.0.3 and v3.0.11 can lead to prototype pollution via the Constructor of the class StyleElement.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | >=4.0.0 <4.0.3 || >=0 <3.0.11 | 4.0.3, 3.0.11 | |
debian 12 | =6.3.2-3 || =6.3.3-1 || =6.3.3-1~bpo11+1 || =6.3.4-1 || =6.3.4-1~bpo11+1 || =6.4.2-1 || =6.4.2-1~bpo11+1 || =6.4.2-2 || =6.4.3-1 || =6.4.3-1~bpo11+1 || =6.4.4-1 || =6.4.5-1 || =6.4.5-1~bpo11+1 || =6.4.5-2 || =6.5.1-1 || =6.5.10-1 || =6.5.10-1~bpo12+1 || =6.5.11-1 || =6.5.11-1~bpo12+1 || =6.5.13-1 || =6.5.14-1 || =6.5.14-1~bpo12+1 || =6.5.15-1 || =6.5.15-2 || =6.5.15-2~bpo12+1 || =6.5.16-1 || =6.5.18-1 || =6.5.18-1~bpo13+1 || =6.5.19-1 || =6.5.20-1 || =6.5.21-1 || =6.5.22-1 || =6.5.22-1~bpo13+1 || =6.5.23-1 || =6.5.23-1~bpo13+1 || =6.5.24-1 || =6.5.24-1~bpo13+1 || =6.5.3-1 || =6.5.3-1~bpo12+1 || =6.5.4-1 || =6.5.4-1~bpo12+1 || =6.5.5-1 || =6.5.5-1~bpo12+1 || =6.5.6-1 || =6.5.6-1~bpo12+1 || =6.5.8-1 || =6.5.8-1~bpo12+1 || =6.5.9-1 || =6.5.9-1~bpo12+1 | - | |
debian 13 | =6.3.2-3 || =6.3.3-1 || =6.3.3-1~bpo11+1 || =6.3.4-1 || =6.3.4-1~bpo11+1 || =6.4.2-1 || =6.4.2-1~bpo11+1 || =6.4.2-2 || =6.4.3-1 || =6.4.3-1~bpo11+1 || =6.4.4-1 || =6.4.5-1 || =6.4.5-1~bpo11+1 || =6.4.5-2 || =6.5.1-1 || =6.5.10-1 || =6.5.10-1~bpo12+1 || =6.5.11-1 || =6.5.11-1~bpo12+1 || =6.5.13-1 || =6.5.14-1 || =6.5.14-1~bpo12+1 || =6.5.15-1 || =6.5.15-2 || =6.5.15-2~bpo12+1 || =6.5.16-1 || =6.5.18-1 || =6.5.18-1~bpo13+1 || =6.5.19-1 || =6.5.20-1 || =6.5.21-1 || =6.5.22-1 || =6.5.22-1~bpo13+1 || =6.5.23-1 || =6.5.23-1~bpo13+1 || =6.5.24-1 || =6.5.24-1~bpo13+1 || =6.5.3-1 || =6.5.3-1~bpo12+1 || =6.5.4-1 || =6.5.4-1~bpo12+1 || =6.5.5-1 || =6.5.5-1~bpo12+1 || =6.5.6-1 || =6.5.6-1~bpo12+1 || =6.5.8-1 || =6.5.8-1~bpo12+1 || =6.5.9-1 || =6.5.9-1~bpo12+1 | - | |
debian 14 | =6.3.2-3 || =6.3.3-1 || =6.3.3-1~bpo11+1 || =6.3.4-1 || =6.3.4-1~bpo11+1 || =6.4.2-1 || =6.4.2-1~bpo11+1 || =6.4.2-2 || =6.4.3-1 || =6.4.3-1~bpo11+1 || =6.4.4-1 || =6.4.5-1 || =6.4.5-1~bpo11+1 || =6.4.5-2 || =6.5.1-1 || =6.5.10-1 || =6.5.10-1~bpo12+1 || =6.5.11-1 || =6.5.11-1~bpo12+1 || =6.5.13-1 || =6.5.14-1 || =6.5.14-1~bpo12+1 || =6.5.15-1 || =6.5.15-2 || =6.5.15-2~bpo12+1 || =6.5.16-1 || =6.5.18-1 || =6.5.18-1~bpo13+1 || =6.5.19-1 || =6.5.20-1 || =6.5.21-1 || =6.5.22-1 || =6.5.22-1~bpo13+1 || =6.5.23-1 || =6.5.23-1~bpo13+1 || =6.5.24-1~bpo13+1 || =6.5.3-1 || =6.5.3-1~bpo12+1 || =6.5.4-1 || =6.5.4-1~bpo12+1 || =6.5.5-1 || =6.5.5-1~bpo12+1 || =6.5.6-1 || =6.5.6-1~bpo12+1 || =6.5.8-1 || =6.5.8-1~bpo12+1 || =6.5.9-1 || =6.5.9-1~bpo12+1 || >=0 <6.5.24-1 | 6.5.24-1 |
Aliases
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.