Description
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The exploit has been disclosed to the public and may be used.
Recommendation
Update the rfc6902 package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.0.0
- Patched version(s): 5.0.0
References
Related Issues
- merge vulnerable to Prototype Pollution - CVE-2021-3645
- deep-defaults vulnerable to prototype pollution - CVE-2021-25944
- mootools-more vulnerable to prototype pollution - CVE-2021-20088
- jszip Vulnerable to Prototype Pollution - CVE-2021-23413
You might also like:
- Tags:
- npm
- rfc6902
Anything's wrong? Let us know Last updated on January 25, 2024


