Description
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
Recommendation
Update the json8 package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.3
- Patched version(s): 1.0.3
References
Could your website be exposed too?
SmartScanner can check your website for Prototype pollution in json8 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype pollution in json8-merge-patch - CVE-2020-8268
- Prototype Pollution in lodash - lodash.set - CVE-2020-8203
- Prototype pollution vulnerability in 'deep-set - CVE-2020-28276
- TypeORM vulnerable to MAID and Prototype Pollution - CVE-2020-8158
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


