Lucene search

K
osvGoogleOSV:CVE-2022-25354
HistoryMar 17, 2022 - 12:15 p.m.

CVE-2022-25354

2022-03-1712:15:08
Google
osv.dev
4
vulnerability
package set-in
prototype pollution
setin method

AI Score

6.6

Confidence

Low

EPSS

0.079

Percentile

94.3%

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. Note: This vulnerability derives from an incomplete fix of CVE-2020-28273

AI Score

6.6

Confidence

Low

EPSS

0.079

Percentile

94.3%