Skip to content

[GHSA-f6v4-cf5j-vf3w] dset Prototype Pollution vulnerability#7459

Closed
Wenxin-Jiang wants to merge 1 commit intomainfrom
Wenxin-Jiang-GHSA-f6v4-cf5j-vf3w
Closed

[GHSA-f6v4-cf5j-vf3w] dset Prototype Pollution vulnerability#7459
Wenxin-Jiang wants to merge 1 commit intomainfrom
Wenxin-Jiang-GHSA-f6v4-cf5j-vf3w

Conversation

@Wenxin-Jiang
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
The vulnerable keys[i] assignment sink is first introduced in 1.0.0's dist/dset.js. 0.0.0 cannot express the prototype-pollution vulnerability because it exports no code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant