SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-28495

However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability.

HIGH 7.3EPSS 3.60%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
3.60% probability · 89th percentile
CISA KEV
Not listed
Affected
totaljs/total.js
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.