Prototype Pollution In object-path
Description
Prototype Pollution in object-path
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). The del() function fails to validate which Object properties it deletes. This allows attackers to modify the prototype of Object, causing the modification of default properties like toString on all objects.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 0.11.8 | ||
debian 11 | 0.11.5-3+deb11u1 | ||
debian 14 | 0.11.8-1 | ||
debian 12 | 0.11.8-1 | ||
debian 13 | 0.11.8-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.