ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-23440
This affects the package set-value before =3.0.0 <4.0.1.

This affects the package set-value before =3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

NVD description · AI analysis pending
9.82% PoC ×3
  • set-value project set-value
  • set-value project communications cloud native core policy
CVE-2019-10747
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1.

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

NVD description · AI analysis pending
9.82% PoC
  • set-value project set-value