PT-2020-19730 · Irrelon · @Irrelon/Path

Beomjin Lee

+1

·

Published

2020-08-18

·

Updated

2022-12-02

·

CVE-2020-7708

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions irrelon-path versions prior to 4.7.0 @irrelon/path versions prior to 4.7.0
Description The issue concerns Prototype Pollution, which can be exploited via the set, unSet, pushVal, and pullVal functions.
Recommendations For irrelon-path versions prior to 4.7.0, update to version 4.7.0 or later. For @irrelon/path versions prior to 4.7.0, update to version 4.7.0 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7708
GHSA-J7CG-H9V9-6VQP
SNYK-JS-IRRELONPATH-598672
SNYK-JS-IRRELONPATH-598673

Affected Products

@Irrelon/Path