Lucene search

K
osvGoogleOSV:GHSA-XCVV-84J5-JW9H
HistoryJul 26, 2018 - 3:12 p.m.

Prototype Pollution in assign-deep

2018-07-2615:12:31
Google
osv.dev
9

0.001 Low

EPSS

Percentile

43.5%

Versions of assign-deep before 0.4.7 are vulnerable to prototype pollution via merging functions.

Recommendation

Update to version 0.4.7 or later.

CPENameOperatorVersion
assign-deeplt0.4.7

0.001 Low

EPSS

Percentile

43.5%