Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Prototype Pollution
Vulnerability Description
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Google Firebase Js Sdk 安全漏洞
Vulnerability Description
Google Firebase Js Sdk是美国谷歌(Google)公司的一个用于连接Firebase后端服务的客户端代码库。 firebase/util 0.3.4之前版本存在安全漏洞,该漏洞源于DeepCopy.ts中的deepExtend函数。攻击者可利用该漏洞可以覆盖和污染程序的对象原型。
CVSS Information
N/A
Vulnerability Type
N/A