VulnerabilityModified
CVE-2020-7765
This vulnerability relates to the deepExtend function within the DeepCopy.ts file.
MEDIUM 5.3EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Affected
- google/firebase\/util
- Source
- report@snyk.io
References
- https://github.com/firebase/firebase-js-sdk/commit/9cf727fcc3d049551b16ae0698ac33dc2fe45adaPatch, Third Party Advisory
- https://github.com/firebase/firebase-js-sdk/pull/4001Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-FIREBASEUTIL-1038324Exploit, Third Party Advisory
- https://github.com/firebase/firebase-js-sdk/commit/9cf727fcc3d049551b16ae0698ac33dc2fe45adaPatch, Third Party Advisory
- https://github.com/firebase/firebase-js-sdk/pull/4001Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-FIREBASEUTIL-1038324Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.