GHSA-4859-gpc7-4j66
Dashboard / Vulnerabilities / GHSA-4859-gpc7-4j66
GHSA-4859-gpc7-4j66
Published: 5 Jun 2019Last Modified: 4 Aug 2021
Summary: Command Injection in dot
Details: All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object's prototype.
Affected packages
Package
Name: dot
Purl: pkg:npm/dot
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
