Vulnerabilities/

Prototype Pollution in js-data (GHSA-c6h4-gc3f-hgjq)

Severity:
High

Description

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of CVE-2020-28442.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
js-data
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing