Lucene search

K
osvGoogleOSV:GHSA-675M-85RW-J3W4
HistoryFeb 07, 2019 - 6:17 p.m.

Prototype Pollution in just-extend

2019-02-0718:17:12
Google
osv.dev
11

EPSS

0.004

Percentile

73.4%

Versions of just-extend before 4.0.0 are vulnerable to prototype pollution. Provided certain input just-extend can add or modify properties of the Object prototype. These properties will be present on all objects.

Recommendation

Update to version 4.0.0 or later.

EPSS

0.004

Percentile

73.4%