PT-2020-19746 · Npm · Worksmith

Nerdjs

·

Published

2020-09-01

·

Updated

2022-12-02

·

CVE-2020-7725

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions worksmith versions prior to 1.0.1
Description The issue concerns Prototype Pollution via the setValue function. This affects all versions up to and including 1.0.0 of the worksmith package.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the setValue function until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-7725
GHSA-9829-JJ5P-J6HF

Affected Products

Worksmith