CRITICAL9.8
GHSA-c6h4-gc3f-hgjq
Prototype Pollution in js-data
Details
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/js-data
Introduced in:
0No fixed version published yet for js-data (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23574[ADVISORY]
- https://github.com/js-data/js-data/issues/576[WEB]
- https://github.com/js-data/js-data/issues/577[WEB]
- https://github.com/js-data/js-data[PACKAGE]
- https://github.com/js-data/js-data/blob/master/dist/js-data.js%23L472[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2320790[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2320791[WEB]
- https://snyk.io/vuln/SNYK-JS-JSDATA-1584361[WEB]