PT-2018-13595 · Npm · Cached-Path-Relative
Cristian-Alexandru Staicu
·
Published
2018-11-06
·
Updated
2023-02-03
·
CVE-2018-16472
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
cached-path-relative versions <=1.0.1
Description
A prototype pollution attack allows an attacker to inject properties on Object.prototype, which are then inherited by all the JS objects through the prototype chain, causing a Denial of Service (DoS) attack.
Recommendations
Update to version 1.0.2 or later.
Fix
DoS
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cached-Path-Relative