CVE-2020-8125

Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
References
Link Resource
https://hackerone.com/reports/778414 Exploit Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:klona_project:klona:*:*:*:*:*:node.js:*:*

Information

Published : 2020-02-04 12:15

Updated : 2020-02-06 10:48


NVD link : CVE-2020-8125

Mitre link : CVE-2020-8125


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

klona_project

  • klona