Lucene search

K
osvGoogleOSV:GHSA-6956-83FG-5WC5
HistoryMar 18, 2022 - 12:01 a.m.

Prototype Pollution in set-in

2022-03-1800:01:11
Google
osv.dev
16
prototype pollution
set-in package
cve-2020-28273

EPSS

0.079

Percentile

94.3%

The package set-in before 2.0.3 is vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. Note: This vulnerability derives from an incomplete fix of CVE-2020-28273

EPSS

0.079

Percentile

94.3%