Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37646
HistoryOct 21, 2022 - 3:21 p.m.

Prototype Pollution

2022-10-2115:21:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
prototype pollution
defnode function
ast.js
malicious property
software

0.006 Low

EPSS

Percentile

78.7%

uglify-js is vulnerable to prototype pollution. The vulnerability exists in DEFNODE function of ast.js via the name variable which allows an attacker to inject malicious property resulting in prototype pollution.

0.006 Low

EPSS

Percentile

78.7%