Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AdonisJS multipart body parsing has Prototype Pollution issue
Vulnerability Description
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
CWE-1321
Vulnerability Title
@adonisjs/lucid 安全漏洞
Vulnerability Description
@adonisjs/lucid是AdonisJS Framework开源的一个数据库对象关系映射库。 @adonisjs/lucid 10.1.3之前版本和11.0.0-next.9之前版本存在安全漏洞,该漏洞源于多部分表单数据解析中存在原型污染,可能导致远程攻击者操纵对象原型。
CVSS Information
N/A
Vulnerability Type
N/A