PT-2020-19673 · None · Class-Transformer

Published

2020-04-06

·

Updated

2022-12-02

·

CVE-2020-7637

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions class-transformer versions prior to 0.3.1
Description The issue allows attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a proto payload.
Recommendations For versions prior to 0.3.1, update to version 0.3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the classToPlainFromExist function until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7637
GHSA-6GP3-H3JJ-PRX4
SNYK-JS-CLASSTRANSFORMER-564431

Affected Products

Class-Transformer