HIGH7.3
GHSA-ff7x-qrg7-qggm
dot-prop Prototype Pollution vulnerability
Quick fix
GHSA-ff7x-qrg7-qggm — dot-prop: upgrade to the fixed version with the command below.
npm install dot-prop@4.2.1Details
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-8116[ADVISORY]
- https://github.com/sindresorhus/dot-prop/issues/63[WEB]
- https://github.com/sindresorhus/dot-prop/commit/3039c8c07f6fdaa8b595ec869ae0895686a7a0f2[WEB]
- https://github.com/sindresorhus/dot-prop/commit/c914124f418f55edea27928e89c94d931babe587[WEB]
- https://hackerone.com/reports/719856[WEB]
- https://github.com/advisories/GHSA-ff7x-qrg7-qggm[ADVISORY]
- https://github.com/sindresorhus/dot-prop[PACKAGE]
- https://github.com/sindresorhus/dot-prop/tree/v4[WEB]