Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zero734Kr

#26079of 53,630
9.8Total CVSS
Vulnerabilities · 1
PT-2022-9014
9.8
2022-12-19
Furqan · Node-Whois · CVE-2020-36618
**Name of the Vulnerable Software and Affected Versions** Furqan node-whois (affected versions not specified) **Description** A critical vulnerability has been found in Furqan node-whois, affecting an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. This issue can be exploited remotely. **Recommendations** To fix this issue, it is recommended to apply a patch with the name 46ccc2aee8d063c7b6b4dee2c2834113b7286076. As a temporary workaround, consider restricting access to the `index.coffee` file until the patch is applied.