PT-2022-11297 · Npm · Assign-Deep
Published
2022-06-30
·
Updated
2022-09-09
·
CVE-2021-40663
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
deep.assign npm package version 0.0.0-alpha.0
Description
The issue is related to Improperly Controlled Modification of Object Prototype Attributes, also known as 'Prototype Pollution'. This occurs when an application does not properly control modifications to object prototype attributes, allowing an attacker to manipulate the prototype chain. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
For deep.assign npm package version 0.0.0-alpha.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Assign-Deep