utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
References
Link | Resource |
---|---|
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C | |
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497 | Exploit Patch Third Party Advisory |
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C | |
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497 | Exploit Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 04:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C - | |
References | () https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497 - Exploit, Patch, Third Party Advisory |
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-11 23:15
Updated : 2024-11-21 04:19
NVD link : CVE-2019-10808
Mitre link : CVE-2019-10808
CVE.ORG link : CVE-2019-10808
JSON object : View
Products Affected
xcritical.software
- utilitify
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')