ZeroHour

CVE-2020-7748

PoC
CVSS 3.1
8.1 high
EPSS
2%p76
Published
()
Modified
Description

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Vendors
ts.ed project
Products
ts.ed
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.