HIGH
Prototype Pollution
Published Oct 20, 2020
8.1
HIGHCVSS 3.1
EPSS 1.72%
Description
This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
Affected products
No data.
- < 5.65.7
No data.
No Red Hat product state for this CVE.
@tsed/core
npm
Introduced 0 Fixed 5.65.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @tsed/core | 0 | 5.65.7 |
Remediation
No remediation recorded yet.
References (5)
- https://github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36 x_refsource_MISCBroken LinkPatchThird Party Advisory
- https://github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761b x_refsource_MISCPatchThird Party Advisory
- https://github.com/advisories/GHSA-77xq-cpvg-7xm2 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7748
- https://snyk.io/vuln/SNYK-JS-TSEDCORE-1019382 x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36 | x_refsource_MISCBroken LinkPatchThird Party Advisory | |
| https://github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761b | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-77xq-cpvg-7xm2 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7748 | ||
| https://snyk.io/vuln/SNYK-JS-TSEDCORE-1019382 | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Oct 20, 2020
Updated Sep 17, 2024
Reserved Jan 21, 2020
Link CVE-2020-7748
CISA Vulnrichment
GHSA-77XQ-CPVG-7XM2 Updated n/a