PT-2018-13593 · Npm · Merge

Asgerf

·

Publicado

2018-10-30

·

Atualizado

2019-10-09

·

CVE-2018-16469

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions merge versions prior to 1.2.1
Description The issue allows the merge.recursive function in the merge package to be tricked into adding or modifying properties of the Object prototype. This can lead to a denial of service attack, as these properties will be present on all objects.
Recommendations Update to version 1.2.1 or later.

Exploit

Correção

Prototype Pollution

Resource Exhaustion

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16469
GHSA-F9CM-QMX5-M98H

Produtos afetados

Merge