PT-2020-19744 · Unknown · Promisehelpers

Nerdjs

·

Published

2020-09-01

·

Updated

2022-12-02

·

CVE-2020-7723

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions promisehelpers versions prior to 0.0.6
Description The issue concerns Prototype Pollution via the insert function. This allows for potential manipulation of object properties.
Recommendations For versions prior to 0.0.6, update to version 0.0.6 or later to resolve the issue.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7723
GHSA-RJ5F-7C8X-GJG4

Affected Products

Promisehelpers