ZeroHour

CVE-2020-15256

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.0.

Vendors
object-path project
Products
object-path
Weakness
CWE-20, CWE-471
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.