Lucene search

K
cvelistHackeroneCVELIST:CVE-2020-8147
HistoryApr 03, 2020 - 8:52 p.m.

CVE-2020-8147

2020-04-0320:52:38
CWE-471
hackerone
www.cve.org
4

AI Score

9.8

Confidence

High

EPSS

0.015

Percentile

86.8%

Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.

CNA Affected

[
  {
    "product": "utils-extend",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "version 1.0.8 and earlier"
      },
      {
        "status": "affected",
        "version": "Not Fixed"
      }
    ]
  }
]

AI Score

9.8

Confidence

High

EPSS

0.015

Percentile

86.8%