OSV 1.4.0 · github-reviewed · 修改于 2021-05-08 05:13
发布时间
2021-05-06 23:45
GitHub 审查时间
2021-05-06 02:39
NVD 发布时间
2021-05-06 21:15
源文件
advisories/github-reviewed/2021/05/GHSA-79jw-6wg7-r9g4/GHSA-79jw-6wg7-r9g4.json
In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
The problem is corrected starting with version 0.5.1.
Issue: https://github.com/adaltas/node-mixme/issues/1 Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028