Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2023-08-01T05:00:01.066Z

Updated: 2023-08-01T05:00:01.066Z

Reserved: 2023-02-20T10:28:48.926Z


Link: CVE-2023-26139

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-08-01T05:15:34.843

Modified: 2023-11-07T04:09:26.930


Link: CVE-2023-26139

JSON object: View

cve-icon Redhat Information

No data.

CWE