Lucene search

K
cvelistSnykCVELIST:CVE-2019-10768
HistoryNov 19, 2019 - 8:07 p.m.

CVE-2019-10768

2019-11-1920:07:49
snyk
www.cve.org
3

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

45.3%

In AngularJS before 1.7.9 the function merge() could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

CNA Affected

[
  {
    "product": "AngularJS",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to version 1.7.9"
      }
    ]
  }
]

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

45.3%