VulnerabilityModified
CVE-2022-25948
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype.
MEDIUM 5.3EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- liquidjs/liquidjs
- Source
- report@snyk.io
References
- https://github.com/harttle/liquidjs/commit/7e99efc5131e20cf3f59e1fc2c371a15aa4109dbPatch, Third Party Advisory
- https://github.com/harttle/liquidjs/commit/7eb621601c2b05d6e379e5ce42219f2b1f556208Patch, Third Party Advisory
- https://github.com/harttle/liquidjs/issues/454Exploit, Issue Tracking, Third Party Advisory
- https://groups.google.com/u/0/a/snyk.io/g/report/c/9ipXecWRtTM/m/IgLadevtCQAJBroken Link
- https://security.snyk.io/vuln/SNYK-JS-LIQUIDJS-2952868Exploit, Patch, Third Party Advisory
- https://github.com/harttle/liquidjs/commit/7e99efc5131e20cf3f59e1fc2c371a15aa4109dbPatch, Third Party Advisory
- https://github.com/harttle/liquidjs/commit/7eb621601c2b05d6e379e5ce42219f2b1f556208Patch, Third Party Advisory
- https://github.com/harttle/liquidjs/issues/454Exploit, Issue Tracking, Third Party Advisory
- https://groups.google.com/u/0/a/snyk.io/g/report/c/9ipXecWRtTM/m/IgLadevtCQAJBroken Link
- https://security.snyk.io/vuln/SNYK-JS-LIQUIDJS-2952868Exploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.