SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7765

This vulnerability relates to the deepExtend function within the DeepCopy.ts file.

MEDIUM 5.3EPSS 0.57%

Does this matter?

Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.

Description

This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.57% probability · 45th percentile
CISA KEV
Not listed
Affected
google/firebase\/util
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.