Dot
Dot Project · 2 CVEs
CVE-2020-7639
MEDIUM
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or…
Apr 6, 2020
CVE-2020-8141
HIGH
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control…
Mar 15, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-7639 | eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototy… | MEDIUM | 1.10% | Apr 6, 2020 |
| CVE-2020-8141 | The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can contro… | HIGH | 2.14% | Mar 15, 2020 |
Showing 1 to 2 of 2 CVEs