EIQ-2020-0009
|
ID |
EIQ-2020-0009 |
|
CVE |
|
|
Description |
minimist enables prototype pollution |
|
Date |
12 Mar 2020 |
|
Severity |
2 - MEDIUM (Snyk score) |
|
CVSSv3 score |
5.6 (Snyk score) |
|
Status |
|
|
Assessment |
minimist versions 1.2.1 and earlier could enable an attacker to inject properties into JavaScript prototype objects (prototype pollution) by exploiting a vulnerability in the recursive merge function execution. An attacker could add or modify object prototype properties of Object.prototype with a constructor or a __proto__ payload. An attacker could leverage prototype pollution by remotely executing arbitrary code, or by triggering JavaScript exceptions to carry out a denial of service (DoS) attack. |
|
Mitigation |
|
|
Affected versions |
2.6.0 and earlier. |
|
Notes |
For more information, see:
See also: |
< Back to all security issues and mitigation actions
In release notes 2.7.0