Description
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
Recommendation
Update the json8 package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.3
- Patched version(s): 1.0.3
References
Related Issues
- Prototype pollution in json8-merge-patch - CVE-2020-8268
- Prototype Pollution in lodash - lodash.set - CVE-2020-8203
- Prototype pollution vulnerability in 'deep-set - CVE-2020-28276
- TypeORM vulnerable to MAID and Prototype Pollution - CVE-2020-8158
You might also like:
- Tags:
- npm
- json8
Anything's wrong? Let us know Last updated on February 01, 2023


