Vulnerabilities/

Prototype Pollution in node-forge util.setPath API

Severity:
Low

Description

forge.util.setPath had a potential prototype pollution issue if called with untrusted keys. This API was not used by forge itself.

Recommendation

Update the node-forge package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-forge
Anything's wrong? Let us know Last updated on January 11, 2023

This issue is available in SmartScanner Professional

See Pricing