VulnerabilityModified
CVE-2019-10792
bodymen before 1.1.1 is vulnerable to Prototype Pollution.
MEDIUM 6.3EPSS 0.96%
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- bodymen project/bodymen
- Source
- report@snyk.io
References
- https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a8653bPatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-BODYMEN-548897Exploit, Third Party Advisory
- https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a8653bPatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-BODYMEN-548897Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.