CVE-2022-25862
PoC —CVSS 3.1
7.5 high
EPSS
<1%p52
Published
()
Modified
Description
This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-7618](https://security.snyk.io/vuln/SNYK-JS-SDS-564123)
- Vendors
- sds project
- Products
- sds
- Weakness
- CWE-1321
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.