PT-2020-9158 · Utilitify · Utilitify

Sam Sanoop

·

Published

2020-03-11

·

Updated

2022-12-02

·

CVE-2019-10808

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions utilitify versions prior to 1.0.3
Description The issue allows modification of object properties. Specifically, the merge method could be tricked into adding or modifying properties of the Object.prototype.
Recommendations For versions prior to 1.0.3, update to version 1.0.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the merge method until a patch is applied.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2019-10808
GHSA-9534-H433-2RJF
SNYK-JS-UTILITIFY-559497

Affected Products

Utilitify