Lucene search

K
nodejsAnonymousNODEJS:1668
HistoryMay 06, 2021 - 3:47 p.m.

Prototype Pollution

2021-05-0615:47:15
Anonymous
www.npmjs.com
18
mixme
prototype pollution
denial of service

EPSS

0.001

Percentile

35.0%

Overview

Impact

In affected versions of mixme an attacker can add or alter properties of an object via ‘proto’ through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

Patches

The problem is corrected starting with version 0.5.1.

Workarounds

No

References

Issue: https://github.com/adaltas/node-mixme/issues/1
Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028

For more information

If you have any questions or comments about this advisory:

Recommendation

Upgrade to version 0.5.1 or later

References

EPSS

0.001

Percentile

35.0%

Related for NODEJS:1668