PT-2018-13593 · Npm · Merge

Asgerf

·

Published

2018-10-30

·

Updated

2019-10-09

·

CVE-2018-16469

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions merge versions prior to 1.2.1
Description The issue allows the merge.recursive function in the merge package to be tricked into adding or modifying properties of the Object prototype. This can lead to a denial of service attack, as these properties will be present on all objects.
Recommendations Update to version 1.2.1 or later.

Exploit

Fix

Prototype Pollution

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16469
GHSA-F9CM-QMX5-M98H

Affected Products

Merge