CVE-2023-26139

7.5HIGH

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to impro

发布于: 8/1/2023更新于: 11/21/2024

描述

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.

AI分析AI驱动

受影响产品

underscore-keypath_projectunderscore-keypath

参考资料