Lucene search

K
redhatcveRedhat.comRH:CVE-2019-10806
HistoryJun 01, 2023 - 9:07 a.m.

CVE-2019-10806

2023-06-0109:07:54
redhat.com
access.redhat.com
8
vega-util
bypass security
access control

EPSS

0.001

Percentile

21.4%

A flaw was found in vega-util prototype which could allow a remote authenticated attacker to bypass security restrictions caused by improper access control. By sending a specially crafted request using the vega.mergeConfig method, an attacker could add or modify the properties of the Object.prototype.

EPSS

0.001

Percentile

21.4%

Related for RH:CVE-2019-10806