Description
All versions of the package progressbar.js prior to 1.1.1 are vulnerable to Prototype Pollution via the function extend() in the file utils.js.
Recommendation
Update the progressbar.js package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.1
- Patched version(s): 1.1.1
References
Related Issues
- rangy vulnerable to Prototype Pollution - CVE-2023-26102
- dot-lens vulnerable to Prototype Pollution - CVE-2023-26106
- Collection.js vulnerable to Prototype Pollution - CVE-2023-26113
- underscore-keypath vulnerable to Prototype Pollution - CVE-2023-26139
You might also like:
- Tags:
- npm
- progressbar.js
Anything's wrong? Let us know Last updated on November 04, 2023


