CVE-2023-26132 Information
Jun 12, 2023
cve
Description
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks via the set() function and the current variable in the /dottie.js file.
Reference
https://security.snyk.io/vuln/SNYK-JS-DOTTIE-3332763 https://github.com/mickhansen/dottie.js/commit/7d3aee1c9c3c842720506e131de7e181e5c8db68 https://github.com/mickhansen/dottie.js/blob/b48e22714aae4489ea6276452f22cc61980ba5a4/dottie.js%23L107
Share on: