VulnerabilityModified
CVE-2020-7770
This affects the package json8 before 1.0.3.
CRITICAL 9.8EPSS 1.89%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- json8 project/json8
- Source
- report@snyk.io
References
- https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7ePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JSON8-1017116Exploit, Third Party Advisory
- https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7ePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JSON8-1017116Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.