Lucene search

K
osvGoogleOSV:CVE-2019-10806
HistoryMar 09, 2020 - 4:15 p.m.

CVE-2019-10806

2020-03-0916:15:11
Google
osv.dev
7

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

21.4%

vega-util prior to 1.13.1 allows manipulation of object prototype. The ‘vega.mergeConfig’ method within vega-util could be tricked into adding or modifying properties of the Object.prototype.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

21.4%