Description
Prototype pollution vulnerability in ‘field’ versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.1, <= 1.0.1
References
- GHSA-hm82-qr45-h7mw
- www.whitesourcesoftware.com
- CVE-2020-28269
- CWE-1321
- CWE-915
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- Prototype Pollution in lodash - lodash-es - CVE-2020-8203
- Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gw - CVE-2020-8203
- Prototype Pollution in decal - decal - CVE-2020-28449
- yargs-parser Vulnerable to Prototype Pollution - CVE-2020-7608
You might also like:
- Tags:
- npm
- field
Anything's wrong? Let us know Last updated on September 08, 2023


