utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497 | Exploit Patch Third Party Advisory |
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1, | Broken Link |
Configurations
Information
Published : 2020-03-11 16:15
Updated : 2022-12-02 11:58
NVD link : CVE-2019-10808
Mitre link : CVE-2019-10808
JSON object : View
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Products Affected
xcritical.software
- utilitify