Description
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
References
https://runkit.com/embed/sq8qjwemyn8t
Third Party AdvisoryURL Repurposed
https://snyk.io/vuln/SNYK-JS-XASSIGN-1759314
ExploitThird Party Advisory
https://runkit.com/embed/sq8qjwemyn8t
Third Party AdvisoryURL Repurposed
https://snyk.io/vuln/SNYK-JS-XASSIGN-1759314
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
8.6 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-20T11:15:07.537Z
4 years agoLast modified
2024-11-21T04:51:47.233Z
1 year ago