VDB
Sign up
HIGH7.5

GHSA-4gxf-g5gf-22h4

dottie vulnerable to Prototype Pollution

Quick fix

GHSA-4gxf-g5gf-22h4 — dottie: upgrade to the fixed version with the command below.

npm install dottie@2.0.4

Details

Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the `set()` function and the current variable in the `/dottie.js` file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dottie
Introduced in: 0Fixed in: 2.0.4
Fixnpm install dottie@2.0.4

References