Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Prototype Pollution
Vulnerability Description
This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
N/A
Vulnerability Title
chart.js 输入验证错误漏洞
Vulnerability Description
chart.js是chatjs团队的一个基于HTML5的JS图形库。 chart.js 2.9.4之前版本存在安全漏洞,该漏洞源于options参数在处理时没有被正确地清除。未检查所设置对象的键。
CVSS Information
N/A
Vulnerability Type
N/A