Description
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
Recommendation
Update the klona package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.1.0
- Patched version(s): 1.1.1
References
Could your website be exposed too?
SmartScanner can check your website for Improper Input Validation in klona and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
- Improper Input Validation in access-policy - CVE-2020-7674
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Improper Neutralization of Input During Web Page Generation in CKEditor4 - CVE-2020-27193
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


