SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7770

This affects the package json8 before 1.0.3.

CRITICAL 9.8EPSS 1.89%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.89% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-1321
Affected
json8 project/json8
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.