Description
Prototype pollution vulnerability in ‘deephas’ versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.0.0, <= 1.0.5
References
- GHSA-4fr2-j4g9-mppf
- www.whitesourcesoftware.com
- CVE-2020-28271
- CWE-1321
- CWE-915
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- Prototype pollution vulnerability in 'deep-set - CVE-2020-28276
- Prototype Pollution in deep-get-set - deep-get-set - CVE-2020-7715
- Prototype Pollution in field - CVE-2020-28269
- Prototype pollution in controlled-merge - CVE-2020-28268
You might also like:
- Tags:
- npm
- deephas
Anything's wrong? Let us know Last updated on September 07, 2023


