VDB
Sign up
HIGH7.1

GHSA-79jw-6wg7-r9g4

Use of Potentially Dangerous Function in mixme

Quick fix

GHSA-79jw-6wg7-r9g4 — mixme: upgrade to the fixed version with the command below.

npm install mixme@0.5.1

Details

### Impact

In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

### Patches The problem is corrected starting with version 0.5.1.

### References Issue: https://github.com/adaltas/node-mixme/issues/1 Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mixme
Introduced in: 0Fixed in: 0.5.1
Fixnpm install mixme@0.5.1

References