Description
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.
Recommendation
Update the dottie package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.4
- Patched version(s): 2.0.4
References
Related Issues
- antfu/utils vulnerable to prototype pollution - CVE-2023-2972
- rangy vulnerable to Prototype Pollution - CVE-2023-26102
- underscore-keypath vulnerable to Prototype Pollution - CVE-2023-26139
- fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name - CVE-2023-26920
You might also like:
- Tags:
- npm
- dottie
Anything's wrong? Let us know Last updated on November 29, 2023


