PT-2020-19743 · Node.Js · Nodee-Utils

Nerdjs

·

Published

2020-09-01

·

Updated

2022-12-02

·

CVE-2020-7722

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nodee-utils versions prior to 1.2.3
Description The issue concerns Prototype Pollution via the deepSet function. This allows for potential manipulation of object properties, which can lead to various security issues.
Recommendations For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider disabling the deepSet function until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7722
GHSA-P6JH-P7Q8-PCRG

Affected Products

Nodee-Utils