VulnerabilityModified
CVE-2020-7618
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
MEDIUM 5.3EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- sds project/sds
- Source
- report@snyk.io
References
- https://github.com/monsterkodi/sds/blob/master/js/set.js#L31Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SDS-564123Exploit, Third Party Advisory
- https://github.com/monsterkodi/sds/blob/master/js/set.js#L31Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SDS-564123Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.