CVE-2020-7792 Information
Jun 07, 2022
cve
Description
This affects all versions of package mout. The deepFillIn function can be used to ‘fill missing properties recursively’ while the deepMixIn ‘mixes objects into the target object recursively mixing existing child objects as well’. In both cases the key used to access the target object recursively is not checked leading to a Prototype Pollution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050373 https://snyk.io/vuln/SNYK-JS-MOUT-1014544 https://github.com/mout/mout/blob/master/src/object/deepMixIn.js https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1050374 https://github.com/mout/mout/blob/master/src/object/deepFillIn.js
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: