PT-2019-12022 · Npm+4 · Mixin-Deep+4

CVE-2019-10746

·

Publicado

2019-08-23

·

Atualizado

2022-10-29

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mixin-deep versions prior to 1.3.2 mixin-deep versions prior to 2.0.1
Description The issue concerns Prototype Pollution, where the mixin-deep function can be tricked into adding or modifying properties of Object.prototype using a constructor payload. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects. The mixinDeep function fails to validate which Object properties it updates.
Recommendations If you are using mixin-deep 2.x, upgrade to version 2.0.1 or later. If you are using mixin-deep 1.x, upgrade to version 1.3.2 or later.

Exploit

Correção

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2021:0549
CESA-2021_0549
CVE-2019-10746
GHSA-FHJF-83WG-R2J9
RHSA-2021:0485
RHSA-2021:0549
RHSA-2021_0549
RLSA-2021:0549
SNYK-JS-MIXINDEEP-450212

Produtos afetados

Almalinux
Centos
Red Hat
Rocky Linux
Mixin-Deep