PT-2022-9026 · Unknown · Hughsk Flat
Hughsk
·
Published
2022-12-25
·
Updated
2024-05-17
·
CVE-2020-36632
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
hughsk flat versions up to 5.0.0
Description
A critical vulnerability was found in hughsk flat, affecting the function
unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. It is possible to initiate the attack remotely.Recommendations
For versions up to 5.0.0, upgrade to version 5.0.1 to address this issue.
As a temporary workaround, consider disabling the
unflatten function until a patch is available.Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hughsk Flat