Lucene search

K
osvGoogleOSV:GHSA-6HWH-RQWF-CXXR
HistoryMay 07, 2021 - 4:32 p.m.

Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util

2021-05-0716:32:02
Google
osv.dev
12
vega-util
manipulation
object prototype
vega.mergeconfig
software security

EPSS

0.001

Percentile

21.4%

vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.

EPSS

0.001

Percentile

21.4%

Related for OSV:GHSA-6HWH-RQWF-CXXR