PT-2020-19735 · Npm · Arr-Flatten-Unflatten

Nerdjs

·

Published

2020-09-01

·

Updated

2022-12-02

·

CVE-2020-7713

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions arr-flatten-unflatten versions up to and including 1.1.4
Description The issue concerns Prototype Pollution via the constructor. This means that an attacker could potentially manipulate the prototype of an object, leading to unintended behavior or security breaches.
Recommendations For versions up to and including 1.1.4, consider avoiding the use of the vulnerable constructor until a patch is available. As a temporary workaround, restrict the use of the arr-flatten-unflatten package to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7713
GHSA-W8F3-PVX4-4C3H

Affected Products

Arr-Flatten-Unflatten