CRITICAL9.8
GHSA-4fr2-j4g9-mppf
Prototype Pollution in deephas
Details
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/deephas
Introduced in:
1.0.0No fixed version published yet for deephas (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-28271[ADVISORY]
- https://github.com/sharpred/deepHas/commit/2fe011713a6178c50f7deb6f039a8e5435981e20[WEB]
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28271[WEB]
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28271,[WEB]