VDB
Sign up
HIGH7.3

GHSA-4m8h-h59m-m34j

Prototype Pollution in bmoor

Quick fix

GHSA-4m8h-h59m-m34j — bmoor: upgrade to the fixed version with the command below.

npm install bmoor@0.10.1

Details

The package bmoor before 0.10.1 is vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bmoor
Introduced in: 0Fixed in: 0.10.1
Fixnpm install bmoor@0.10.1

References