Lucene search

K
osvGoogleOSV:GHSA-2CF2-2383-H4JV
HistoryMay 07, 2021 - 4:16 p.m.

Improperly Controlled Modification of Dynamically-Determined Object Attributes in querymen

2021-05-0716:16:43
Google
osv.dev
5

0.001 Low

EPSS

Percentile

38.8%

querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

CPENameOperatorVersion
querymenlt2.1.4

0.001 Low

EPSS

Percentile

38.8%

Related for OSV:GHSA-2CF2-2383-H4JV