Lucene search

K
osvGoogleOSV:CVE-2018-3728
HistoryMar 30, 2018 - 7:29 p.m.

CVE-2018-3728

2018-03-3019:29:00
Google
osv.dev
11

AI Score

8.8

Confidence

High

EPSS

0.01

Percentile

84.0%

hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via ‘merge’ and ‘applyToDefaults’ functions, which allows a malicious user to modify the prototype of “Object” via proto, causing the addition or modification of an existing property that will exist on all objects.

AI Score

8.8

Confidence

High

EPSS

0.01

Percentile

84.0%