• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-1321

CVE-2020-7788

February 26, 2023 by

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-7792

February 26, 2023 by

This affects all versions of package mout. The deepFillIn function can be used to ‘fill missing properties recursively’, while the deepMixIn ‘mixes objects into the target object, recursively mixing existing child objects as well’. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.

CVE-2020-7723

February 26, 2023 by

All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

CVE-2020-7724

February 26, 2023 by

All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.

CVE-2020-7725

February 26, 2023 by

All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

CVE-2020-7726

February 26, 2023 by

All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

  • « Go to Previous Page
  • Go to page 1
  • Go to page 2
  • Go to page 3
  • Go to page 4
  • Go to page 5
  • Interim pages omitted …
  • Go to page 37
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE