9.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
0.003 Low
EPSS
Percentile
65.3%
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key
variable in grunt-karma.js
.
CPE | Name | Operator | Version |
---|---|---|---|
grunt-karma | le | 4.0.1 |
github.com/advisories/GHSA-hcj4-xf6x-63wj
github.com/karma-runner/grunt-karma/blob/45b925964f55870f375c6e670d9945b223c984f5/tasks/grunt-karma.js#L109
github.com/karma-runner/grunt-karma/blob/45b925964f55870f375c6e670d9945b223c984f5/tasks/grunt-karma.js#L26
github.com/karma-runner/grunt-karma/issues/311
nvd.nist.gov/vuln/detail/CVE-2022-37602