[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-3750 -- node-deep-extend

ID: oval:org.secpod.oval:def:2000699Date: (C)2019-04-22   (M)2023-07-17
Class: VULNERABILITYFamily: unix




The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

Platform:
Debian 9.x
Product:
node-deep-extend
Reference:
CVE-2018-3750
CVE    1
CVE-2018-3750
CPE    2
cpe:/a:github:node-deep-extend
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies