VulnerabilityModified
CVE-2019-10795
undefsafe before 2.0.3 is vulnerable to Prototype Pollution.
MEDIUM 6.3EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- undefsafe project/undefsafe
- Source
- report@snyk.io
References
- https://github.com/remy/undefsafe/commit/f272681b3a50e2c4cbb6a8533795e1453382c822Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-UNDEFSAFE-548940Exploit, Third Party Advisory
- https://github.com/remy/undefsafe/commit/f272681b3a50e2c4cbb6a8533795e1453382c822Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-UNDEFSAFE-548940Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.