Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13292
HistoryFeb 04, 2019 - 1:17 a.m.

Prototype Pollution

2019-02-0401:17:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

73.4%

node.extend is vulnerable to prototype pollution attacks. An attacker is able to inject arbitrary properties into Object.prototype to add or modify properties due to a lack of object validation.

CPENameOperatorVersion
node.extendeq2.0.0
node.extendle1.1.6