Lucene search

K
githubGitHub Advisory DatabaseGHSA-C429-5P7V-VGJP
HistorySep 25, 2022 - 12:00 a.m.

hoek subject to prototype pollution via the clone function.

2022-09-2500:00:27
CWE-1321
GitHub Advisory Database
github.com
97
hoek
prototype pollution
clone function
vulnerability
software update

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%

hoek versions prior to 8.5.1, and 9.x prior to 9.0.3 are vulnerable to prototype pollution in the clone function. If an object with the proto key is passed to clone() the key is converted to a prototype. This issue has been patched in version 9.0.3, and backported to 8.5.1.

Affected configurations

Vulners
Node
hoekRange6.1.3
OR
hapihoekRange9.0.09.0.3
OR
hapihoekRange<8.5.1
VendorProductVersionCPE
*hoek*cpe:2.3:a:*:hoek:*:*:*:*:*:*:*:*
hapihoek*cpe:2.3:a:hapi:hoek:*:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%