Lucene search

K
osvGoogleOSV:GHSA-FHV8-FX5F-7FXF
HistorySep 20, 2021 - 7:53 p.m.

Prototype Pollution in the merge and clone helper methods

2021-09-2019:53:15
Google
osv.dev
12
impact
prototype pollution
merge
clone
helper methods
core util
apache echarts
data visualization library
patched
zrender
echarts
update
software

EPSS

0.002

Percentile

64.7%

Impact

Using merge and clone helper methods in the src/core/util.ts module will have prototype pollution. It will affect the popular data visualization library Apache ECharts, which is using and exported these two methods directly.

Patches

It has been patched in https://github.com/ecomfe/zrender/pull/826.
Users should update zrender to 5.2.1. and update echarts to 5.2.1 if project is using echarts.

EPSS

0.002

Percentile

64.7%

Related for OSV:GHSA-FHV8-FX5F-7FXF