This repository has been archived by the owner on Dec 9, 2023. It is now read-only.
CVE-2020-15256 (High) detected in object-path-0.9.2.tgz #159
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-15256 - High Severity Vulnerability
Access deep properties using a path
Library home page: https://registry.npmjs.org/object-path/-/object-path-0.9.2.tgz
Path to dependency file: /Website/package.json
Path to vulnerable library: Website/node_modules/object-path/package.json
Dependency Hierarchy:
A prototype pollution vulnerability has been found in
object-path
<= 0.11.4 affecting theset()
method. The vulnerability is limited to theincludeInheritedProps
mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance ofobject-path
and setting the optionincludeInheritedProps: true
, or by using the defaultwithInheritedProps
instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage ofset()
in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a workaround, don't use theincludeInheritedProps: true
options or thewithInheritedProps
instance if using a version >= 0.11.0.Publish Date: 2020-10-19
URL: CVE-2020-15256
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-cwx2-736x-mf6w
Release Date: 2020-07-21
Fix Resolution: 0.11.5
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: