Description
This vulnerability affects all versions of package x-assign. The global proto object can be polluted using the proto object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.1.4
References
- GHSA-4mvj-rq4v-2fxw
- runkit.com
- snyk.io
- CVE-2021-23452
- CWE-1321
- CWE-915
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- Prototype Pollution in record-like-deep-assign - CVE-2021-23402
- deep-defaults vulnerable to prototype pollution - CVE-2021-25944
- MrSwitch hello.js vulnerable to prototype pollution - CVE-2021-26505
- Prototype Pollution in dotty - dotty - CVE-2021-23624
You might also like:
- Tags:
- npm
- x-assign
Anything's wrong? Let us know Last updated on January 27, 2023


