PT-2019-9311 · Npm · Just-Extend

Asgerf

·

Publicado

2019-02-01

·

Atualizado

2019-10-09

·

CVE-2018-16489

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions just-extend versions prior to 4.0.0
Description A prototype pollution issue allows an attack to inject properties onto Object.prototype through its functions, potentially adding or modifying properties of the Object prototype. These properties will be present on all objects.
Recommendations Update to version 4.0.0 or later.

Exploit

Correção

Special Elements Injection

Prototype Pollution

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16489
GHSA-675M-85RW-J3W4

Produtos afetados

Just-Extend