Vulnerabilities/

dustjs-linkedin vulnerable to Prototype Pollution

Severity:
High

Description

A vulnerability was found in LinkedIn dustjs prior to version 3.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The attack may be launched remotely.

Recommendation

Update the dustjs-linkedin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dustjs-linkedin
Anything's wrong? Let us know Last updated on January 28, 2023

This issue is available in SmartScanner Professional

See Pricing