EIQ-2020-0009#
ID |
EIQ-2020-0009 |
---|---|
CVE |
|
Description |
minimist enables prototype pollution |
Date |
12 Mar 2020 |
Severity |
2 - MEDIUM(Snyk score) |
CVSSv3 score |
5.6 (Snyk score) |
Status |
✅ 2.7.0 |
Assessment |
minimist versions 1.2.1 and earlier could enable an attacker to inject properties into JavaScript prototype objects (prototype pollution) by exploiting a vulnerability in the recursive merge function execution. An attacker could add or modify object prototype properties of Object.prototype with a constructor or a Modified properties are propagated to all objects through inheritance. An attacker could leverage prototype pollution by remotely executing arbitrary code, or by triggering JavaScript exceptions to carry out a denial of service (DoS) attack. |
Mitigation |
|
Affected versions |
2.6.0 and earlier. |
Notes |
For more information, see: |