PT-2020-21457 · Unknown · Safe-Object2
Published
2020-09-04
·
Updated
2020-09-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
safe-object2 versions all
Description
The issue concerns prototype pollution, where the
settter() function fails to restrict modifications to an Object's prototype. This could allow an attacker to add or modify existing properties that will be present on all objects.Recommendations
For all versions, consider using an alternative package until a fix is made available. As a temporary workaround, consider disabling the
settter() function to minimize the risk of exploitation.Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safe-Object2