Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
1024bit extend-deep index.js prototype pollution
Vulnerability Description
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The code repository of the project has not been active for many years.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
extend-deep 安全漏洞
Vulnerability Description
extend-deep是杭盖个人开发者的一个深度递归合并对象的JavaScript工具库。 extend-deep 0.1.6及之前版本存在安全漏洞,该漏洞源于对文件index.js中参数__proto__的操作不当,可能导致对象原型属性被不当修改。
CVSS Information
N/A
Vulnerability Type
N/A