HIGH7.5
GHSA-39qv-prmh-x37f
Prototype Pollution in @strikeentco/set
Quick fix
GHSA-39qv-prmh-x37f — @strikeentco/set: upgrade to the fixed version with the command below.
npm install @strikeentco/set@1.0.2Details
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23497[ADVISORY]
- https://github.com/strikeentco/set/commit/b2f942c[WEB]
- https://github.com/strikeentco/set[WEB]
- https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821[WEB]
- https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation[WEB]
- https://snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-2385945[WEB]