Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Prototype Pollution
Vulnerability Description
The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
N/A
Vulnerability Title
Ahdinosaur Set-in 安全漏洞
Vulnerability Description
Ahdinosaur Set-in是Ahdinosaur个人开发者的一个基于Js可对嵌套关联结构的键进行赋值的代码库。 Ahdinosaur Set-in 存在安全漏洞,该漏洞允许攻击者将对象原型合并到其中。
CVSS Information
N/A
Vulnerability Type
N/A