PT-2020-9156 · Vega-Util · Vega-Util

Published

2020-03-09

·

Updated

2022-12-02

·

CVE-2019-10806

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions vega-util versions prior to 1.13.1
Description The issue allows manipulation of the object prototype. The vega.mergeConfig method within vega-util can be tricked into adding or modifying properties of the Object.prototype.
Recommendations For versions prior to 1.13.1, update to version 1.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vega.mergeConfig method until a patch is applied.

Exploit

Fix

Prototype Pollution

RCE

Weakness Enumeration

Related Identifiers

CVE-2019-10806
GHSA-6HWH-RQWF-CXXR
SNYK-JS-VEGAUTIL-559223

Affected Products

Vega-Util