Vulnerabilities/

Uncontrolled Resource Consumption in fun-map

Severity:
High

Description

fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
fun-map
Anything's wrong? Let us know Last updated on January 27, 2023