VDB
Sign up
CRITICAL9.8

GHSA-pf2j-9qmp-jqr2

TypeORM vulnerable to MAID and Prototype Pollution

Quick fix

GHSA-pf2j-9qmp-jqr2 — typeorm: upgrade to the fixed version with the command below.

npm install typeorm@0.2.25

Details

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/typeorm
Introduced in: 0Fixed in: 0.2.25
Fixnpm install typeorm@0.2.25

References