ZeroHour

CVE-2020-7770

PoC
CVSS 3.1
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

Vendors
json8 project
Products
json8
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.