PT-2018-16146 · Npm · Merge-Deep

Holyvier

·

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2018-3722

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions merge-deep versions prior to 3.0.1
Description The issue allows a malicious user to modify the prototype of Object via proto, causing the addition or modification of an existing property that will exist on all objects. This is achieved through prototype pollution via merging functions.
Recommendations Update to version 3.0.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3722
GHSA-9G9W-HMVJ-5H57

Affected Products

Merge-Deep