HIGH
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0
Published Aug 20, 2019
7.5
HIGHCVSS 3.1
EPSS 1.14%
Description
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
Affected products
- Vendor n/a Product Assign-Deep Defaultn/a
- Version All versions prior to 0.4.8 and version 1.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Assign-Deep | n/a |
|
OR
- < 0.4.8
- 1.0.0
No data.
No Red Hat product state for this CVE.
assign-deep
npm
Introduced 0 Fixed 0.4.8assign-deep
npm
Introduced 1.0.0 Fixed 1.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | assign-deep | 0 | 0.4.8 |
| npm | assign-deep | 1.0.0 | 1.0.1 |
Remediation
No remediation recorded yet.
Weaknesses (3)
References (6)
- https://github.com/advisories/GHSA-66rh-8fw6-59q6 Advisory
- https://github.com/jonschlinkert/assign-deep/commit/8e3cc4a34246733672c71e96532105384937e56c
- https://github.com/jonschlinkert/assign-deep/commit/90bf1c551d05940898168d04066bbf15060f50cc
- https://nvd.nist.gov/vuln/detail/CVE-2019-10745
- https://snyk.io/vuln/SNYK-JS-ASSIGNDEEP-450211 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://www.npmjs.com/advisories/1014
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Aug 20, 2019
Updated Aug 4, 2024
Reserved Apr 3, 2019
Link CVE-2019-10745
CISA Vulnrichment
GHSA-66RH-8FW6-59Q6 Updated n/a