Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27677
HistoryOct 27, 2020 - 2:53 a.m.

Prototype Pollution

2020-10-2702:53:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
pathval
prototype pollution
parsepath
attacker
control
attributes.

EPSS

0.001

Percentile

40.7%

pathval is vulnerable to prototype pollution. The function parsePath allows an attacker to get control of value of “path” and modify attributes such as __proto__, constructor and prototype.

EPSS

0.001

Percentile

40.7%