PT-2020-19764 · Tsed · @Tsed/Core
Sam Sanoop
·
Published
2020-10-20
·
Updated
2022-12-02
·
CVE-2020-7748
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
@tsed/core versions prior to 5.65.7
Description
This issue relates to the
deepExtend function, part of the utils directory. Depending on user input, an attacker can overwrite and pollute the object prototype of a program.Recommendations
For versions prior to 5.65.7, update to version 5.65.7 or later to resolve the issue. As a temporary workaround, consider restricting user input to prevent exploitation of the
deepExtend function.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Tsed/Core