HIGH7.5
GHSA-8v63-cqqc-6r2c
Prototype Pollution in object-path
Quick fix
GHSA-8v63-cqqc-6r2c — object-path: upgrade to the fixed version with the command below.
npm install object-path@0.11.8Details
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). The `del()` function fails to validate which Object properties it deletes. This allows attackers to modify the prototype of Object, causing the modification of default properties like `toString` on all objects.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-3805[ADVISORY]
- https://github.com/mariocasciaro/object-path/commit/4f0903fd7c832d12ccbe0d9c3d7e25d985e9e884[WEB]
- https://github.com/mariocasciaro/object-path[PACKAGE]
- https://huntr.dev/bounties/571e3baf-7c46-46e3-9003-ba7e4e623053[WEB]
- https://lists.debian.org/debian-lts-announce/2023/01/msg00031.html[WEB]