GHSA-8j4w-5fw4-rm27
Dashboard / Vulnerabilities / GHSA-8j4w-5fw4-rm27
Summary: Prototype Pollution in deeply
Details: Versions of `deeply` prior to 1.0.1 are vulnerable to Prototype Pollution. The package fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects. ## Recommendation Upgrade to version 3.1.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10750, https://snyk.io/vuln/SNYK-JS-DEEPLY-451026, https://www.npmjs.com/advisories/1030
Affected packages
Package
Name: deeply
Purl: pkg:npm/deeply
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -3.1.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
