GHSA-79jw-6wg7-r9g4
Dashboard / Vulnerabilities / GHSA-79jw-6wg7-r9g4
GHSA-79jw-6wg7-r9g4
Summary: Use of Potentially Dangerous Function in mixme
Details: ### Impact In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS). ### Patches The problem is corrected starting with version 0.5.1. ### References Issue: https://github.com/adaltas/node-mixme/issues/1 Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028
References: https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4, https://nvd.nist.gov/vuln/detail/CVE-2021-29491, https://security.netapp.com/advisory/ntap-20210622-0002
Affected packages
Package
Name: mixme
Purl: pkg:npm/mixme
Affected ranges
Type: SEMVER
Events:
