PT-2020-19962 · Npm · Klona

Skyn3T

·

Published

2020-02-04

·

Updated

2021-04-13

·

CVE-2020-8125

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions klona versions 1.1.0 and earlier
Description A flaw in input validation in the npm package klona may allow a prototype pollution attack, potentially resulting in remote code execution or denial of service of applications using klona.
Recommendations For klona versions 1.1.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8125
GHSA-8F89-2FWJ-5V5R

Affected Products

Klona