Back to search
CVE-2019-10747
Published: Aug 23, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
| Vendor | Product | Versions |
|---|---|---|
n/a | set-value | affected All versions before 2.0.1 and version 3.0.0 |
References
https://snyk.io/vuln/SNYK-JS-SETVALUE-450213
x_refsource_MISC
[drat-dev] 20191029 [GitHub] [drat] ottlinger opened a new issue #202: Fix security issue in set-value
mailing-list
x_refsource_MLIST
FEDORA-2020-1f1c94907b
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-582515fa8a
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now