Lucene search

K
osvGoogleOSV:GHSA-CXM3-284P-QC4V
HistorySep 03, 2020 - 3:53 p.m.

Prototype Pollution in sds

2020-09-0315:53:12
Google
osv.dev
12
sds
prototype pollution
upgrade

EPSS

0.001

Percentile

38.8%

Affected versions of sds are vulnerable to prototype pollution. The set function does not restrict the modification of an Object’s prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.

Recommendation

Upgrade to version 4.0.0 or later

EPSS

0.001

Percentile

38.8%

Related for OSV:GHSA-CXM3-284P-QC4V