Prototype Pollution in madlib-object-utils
High severity
GitHub Reviewed
Published
Apr 16, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 15, 2022
Published to the GitHub Advisory Database
Apr 16, 2022
Reviewed
Apr 22, 2022
Last updated
Jan 27, 2023
The package madlib-object-utils before version 0.1.8 is vulnerable to Prototype Pollution via the
setValue
method, as it allows an attacker to merge object prototypes into it. Note: This vulnerability derives from an incomplete fix of CVE-2020-7701References