Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35562
HistoryMay 17, 2022 - 4:18 a.m.

Prototype Pollution

2022-05-1704:18:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
vulnerability
prototype pollution
incomplete cve-2020-7618
injection of attributes
object.prototype
set function

EPSS

0.001

Percentile

38.8%

sds is vulnerable to prototype pollution.The vulnerability exists due to an incomplete of CVE-2020-7618 where an injection of attributes can pollute the properties of the Object.prototype by the attacker using the set function in js/set.js,

EPSS

0.001

Percentile

38.8%