VDB
Sign up
MEDIUM6.5

GHSA-23wx-cgxq-vpwx

Prototype Pollution in dset

Quick fix

GHSA-23wx-cgxq-vpwx — dset: upgrade to the fixed version with the command below.

npm install dset@3.1.2

Details

All versions of `dset` prior to 3.1.2 are vulnerable to Prototype Pollution via `dset/merge` mode, as the `dset` function checks for prototype pollution by validating if the top-level path contains `__proto__`, `constructor` or `prototype`. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dset
Introduced in: 0Fixed in: 3.1.2
Fixnpm install dset@3.1.2
Maven/org.webjars.npm:dset
Introduced in: 0Fixed in: 3.1.2
Fix# pom.xml: bump <version>3.1.2</version> for org.webjars.npm:dset

References