This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-NEDB-1305279 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-06-15 13:15
Updated : 2021-06-23 19:35
NVD link : CVE-2021-23395
Mitre link : CVE-2021-23395
JSON object : View
CWE
Products Affected
nedb_project
- nedb