VulnerabilityModified
CVE-2020-7600
querymen prior to 2.1.4 allows modification of object properties.
MEDIUM 5.3EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- querymen project/querymen
- Source
- report@snyk.io
References
- https://github.com/diegohaz/querymen/commit/1987fefcb3b7508253a29502a008d5063a873cefExploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-QUERYMEN-559867Patch, Third Party Advisory
- https://github.com/diegohaz/querymen/commit/1987fefcb3b7508253a29502a008d5063a873cefExploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-QUERYMEN-559867Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.