Description
Prototype pollution vulnerability in ‘deepref’ versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.1.1, <= 1.2.1
References
Related Issues
- dot-prop Prototype Pollution vulnerability - CVE-2020-8116
- eivindfjeldstad-dot contains prototype pollution vulnerability - CVE-2020-7639
- Prototype pollution vulnerability in 'libnested - CVE-2020-28283
- Prototype pollution vulnerability in 'deep-set - CVE-2020-28276
You might also like:
- Tags:
- npm
- deepref
Anything's wrong? Let us know Last updated on February 01, 2023


