utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497 | Exploit Patch Third Party Advisory |
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C |
Configurations
History
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-11 23:15
Updated : 2023-11-07 03:02
NVD link : CVE-2019-10808
Mitre link : CVE-2019-10808
JSON object : View
Products Affected
xcritical.software
- utilitify
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')