Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40407
HistoryMay 08, 2023 - 2:35 a.m.

Prototype Pollution

2023-05-0802:35:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
vulnerability
prototype pollution
meta.ts
resolvemetadatarecord
meta decoder
metadatarecord
software

EPSS

0.001

Percentile

32.3%

@aedart/support is vulnerable to Prototype Pollution. The vulnerability exists in the resolveMetadataRecord function of meta.ts when merged with a base class metadata object in the meta decoder, which allows an attacker to inject properties into existing prototypes via the MetadataRecord attribute.

EPSS

0.001

Percentile

32.3%