Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
brikcss merge prototype pollution
Vulnerability Description
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
merge 安全漏洞
Vulnerability Description
merge是brikcss开源的一个递归合并 JavaScript 对象的工具。 merge 1.3.0及之前版本存在安全漏洞,该漏洞源于对参数__proto__/constructor.prototype/prototype的操作不当,可能导致对象原型属性被不当修改。
CVSS Information
N/A
Vulnerability Type
N/A