漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
Vulnerability Description
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
Sascha Goldhofer json-schema-library 输入验证错误漏洞
Vulnerability Description
Sascha Goldhofer json-schema-library是Sascha Goldhofer组织的一款JSON模式验证库。 Sascha Goldhofer json-schema-library 11.5.0版本和11.5.1版本存在安全漏洞,该漏洞源于文件src/keywords/propertyDependencies.ts中parsePropertyDependencies函数对对象原型属性的修改控制不当,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A