Description
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
Recommendation
Update the klona package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.1.0
- Patched version(s): 1.1.1
References
Related Issues
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
- Improper Input Validation in access-policy - CVE-2020-7674
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Improper Neutralization of Input During Web Page Generation in CKEditor4 - CVE-2020-27193
You might also like:
- Tags:
- npm
- klona
Anything's wrong? Let us know Last updated on February 01, 2023


