VDB
Sign up
HIGH7.3

GHSA-4jqc-8m5r-9rpr

Prototype Pollution in set-value

Quick fix

GHSA-4jqc-8m5r-9rpr — set-value: upgrade to the fixed version with the command below.

npm install set-value@4.0.1

Details

This affects the package `set-value`. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/set-value
Introduced in: 4.0.0Fixed in: 4.0.1
Fixnpm install set-value@4.0.1
NuGet/set-value-nuget
Introduced in: 0Fixed in: 2.0.0
Fixdotnet add package set-value-nuget --version 2.0.0
npm/set-value
Introduced in: 0Fixed in: 2.0.1
Fixnpm install set-value@2.0.1
npm/set-value
Introduced in: 3.0.0Fixed in: 3.0.3
Fixnpm install set-value@3.0.3

References