PT-2020-19656 · Npm · Express-Mock-Middleware
Published
2020-04-07
·
Updated
2022-12-02
·
CVE-2020-7616
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
express-mock-middleware versions 0.0.0 through 0.0.6
Description
The issue allows exported functions by the package to be tricked into adding or modifying properties of the
Object.prototype, which can be exploited by creating a new directory with attack code that will be exported by express-mock-middleware. This is considered a low-risk issue.Recommendations
For express-mock-middleware versions 0.0.0 through 0.0.6, consider updating to a version that fixes the Prototype Pollution issue, as the current version can be exploited by manipulating the
Object.prototype.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Express-Mock-Middleware