icon

We found results for “

WS-2019-0251

Date: September 11, 2019

In smart-extend, all versions are vulnerable to Prototype Pollution when deep() function allows attackers to modify the prototype of Object causing the addition or modification of an existing property that will exist on all objects.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-1321

CVSS v3

Base Score:
Attack Vector (AV):
Attack Complexity (AC):
Privileges Required (PR):
User Interaction (UI):
Scope (S):
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE

Do you need more information?

Contact Us