PT-2022-9026 · Unknown · Hughsk Flat

Hughsk

·

Published

2022-12-25

·

Updated

2024-05-17

·

CVE-2020-36632

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions hughsk flat versions up to 5.0.0
Description A critical vulnerability was found in hughsk flat, affecting the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. It is possible to initiate the attack remotely.
Recommendations For versions up to 5.0.0, upgrade to version 5.0.1 to address this issue. As a temporary workaround, consider disabling the unflatten function until a patch is available.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-36632
GHSA-2J2X-2GPW-G8FM

Affected Products

Hughsk Flat