Description
Affected versions of @polymer/polymer are vulnerable to prototype pollution. The package fails to prevent modification of object prototypes through chart options containing a payload such as {"__proto__": {"polluted": true}}. It is possible to achieve the same results if a chart loads data from a malicious server.
Recommendation
Update the chartkick package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.1.0, <= 3.1.3
- Patched version(s): 3.2.0
References
Related Issues
- angular Prototype Pollution vulnerability - CVE-2019-10768
- Prototype Pollution in deeply - CVE-2019-10750
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 3 - CVE-2019-10744
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 4 - CVE-2019-10744
- Tags:
- npm
- chartkick
Anything's wrong? Let us know Last updated on January 26, 2023