Lucene search

K
cvelistMendCVELIST:CVE-2020-28272
HistoryDec 02, 2020 - 2:32 p.m.

CVE-2020-28272

2020-12-0214:32:00
Mend
www.cve.org
3
vulnerability
keyget
denial of service
remote code execution
version 1.0.0
version 2.2.0
prototype pollution

AI Score

7.7

Confidence

High

EPSS

0.017

Percentile

87.9%

Prototype pollution vulnerability in ‘keyget’ versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

CNA Affected

[
  {
    "product": "keyget",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.1, 2.0.0, 2.0.1, 2.1.0, 2.2.0"
      }
    ]
  }
]

AI Score

7.7

Confidence

High

EPSS

0.017

Percentile

87.9%