Lucene search

K
nodejsAnonymousNODEJS:1774
HistoryAug 10, 2021 - 4:10 p.m.

Prototype Pollution

2021-08-1016:10:19
Anonymous
www.npmjs.com
45

0.002 Low

EPSS

Percentile

54.9%

Overview

Affected versions of jszip have a prototype pollution vulnerability. Crafting a new zip file with filenames set to Object prototype values (e.g proto, toString, etc) results in a returned object with a modified prototype instance.

Recommendation

Upgrade to version 3.7.0 or later

References

CPENameOperatorVersion
jsziplt3.7.0