CVE-2020-7770
PoC —CVSS 3.1
9.8 critical
EPSS
2%p78
Published
()
Modified
Description
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
- Vendors
- json8 project
- Products
- json8
- Weakness
- CWE-1321
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.