ZeroHour

CVE-2020-7765

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p45
Published
()
Modified
Description

This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Vendors
google
Products
firebase\/util
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.